IBM Security Bulletin: Security vulnerability about Apache Tomcat JSP file upload in WebSphere Application Server Community Edition 3.0.0.4
|
Información sobre el sistema
|
|
|
Software afectado |
IBM |
Descripción
|
Unrestricted file upload vulnerability in Apache Tomcat which is shipped with WASCE 3.0.0.4, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file. CVE(s): CVE-2013-4444 Affected product(s) and affected version(s): WebSphere Application Server Community Edition 3.0.0.4 Refer to the following reference URLs for remediation and additional vulnerability details:
More info:
https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_security_vulnerability_about_apache_tomcat_jsp_file_upload_in_websphere_application_server_community_edition_3_0_0_4?lang=en_us |
Identificadores estándar
|
Propiedad |
Valor |
CVE |
CVE-2013-4444 ,CVE-2014-6097 ,CVE-2014-3511 ,CVE-2014-5139 ,CVE-2014-4263 ,CVE-2014-0139 ,CVE-2014-0138 ,CVE-2014-6394 and CVE-2014-7191. |