Boletines de Vulnerabilidades

IBM Security Bulletin: Security vulnerability about Apache Tomcat JSP file upload in WebSphere Application Server Community Edition 3.0.0.4


Información sobre el sistema

   
Software afectado IBM

Descripción

Unrestricted file upload vulnerability in Apache Tomcat which is shipped with WASCE 3.0.0.4, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file. CVE(s): CVE-2013-4444 Affected product(s) and affected version(s): WebSphere Application Server Community Edition 3.0.0.4 Refer to the following reference URLs for remediation and additional vulnerability details:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_security_vulnerability_about_apache_tomcat_jsp_file_upload_in_websphere_application_server_community_edition_3_0_0_4?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2013-4444 ,CVE-2014-6097 ,CVE-2014-3511 ,CVE-2014-5139 ,CVE-2014-4263 ,CVE-2014-0139 ,CVE-2014-0138 ,CVE-2014-6394 and CVE-2014-7191.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-11-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT