Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in IBM InfoSphere Guardium Database Activity Monitoring (CVE-2011-4858)


Información sobre el sistema

   
Software afectado IBM

Descripción

Apache Tomcat is vulnerable to a denial of service, caused by insufficient randomization of hash data structures. By sending multiple specially-crafted HTTP POST requests to an affected application containing conflicting hash key values, a remote attacker could exploit this vulnerability to cause the consumption of CPU resources. CVE(s): CVE-2011-4858 Affected product(s) and affected version(s): Versions 8.0, 8.1, and 8.2 of IBM InfoSphere Guardium Database Activity Monitoring Refer to

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ibm_infosphere_guardium_database_activity_monitoring_cve_2011_4858?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2011-4858 ,CVE-2014-0094 ,CVE-2014-0112 ,CVE-2014-0113 ,CVE-2014-0116 ,CVE-2014-0963 and CVE-2014-0935.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-06-06

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT