Boletines de Vulnerabilidades |
IBM Security Bulletin: Open Source Apache Tomcat vulnerability and vulnerability in Diffie-Hellman ciphers affects IBM Tivoli Application Dependency Discovery Manager (TADDM) (CVE-2014-0230, CVE-2014- |
|
| Software afectado | IBM |
|
First two issues could affect Apache Tomcat that is embedded in TADDM (X-Force reports dated 9 April 2015 and 14 May 2015). One of them is related to a denial of service (DoS) attack that can occur, because there was no limit to the size of a request body that Tomcat could swallow. Other vulnerability allows the use of expression language to bypass the protections of a Security Manager. The expressions were evaluated within a privileged code section. Last issue is commonly referred to as More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_open_source_apache_tomcat_vulnerability_and_vulnerability_in_diffie_hellman_ciphers_affects_ibm_tivoli_application_dependency_discovery_manager_taddm_cve_2014_0230_cve_2014_7 |
|














