Boletines de Vulnerabilidades

IBM Security Bulletin: Open Source Apache Struts V1 ClassLoader manipulation vulnerability affecting IBM Tivoli Network Manager(CVE-2014-0114).


Información sobre el sistema

   
Software afectado IBM

Descripción

A security vulnerablitity has been identified in IBM Tivoli Network Manager. Moreover, the same vulnerability has been identified in Tivoli Integrated Portal (TIP) and IBM WebSphere Application Server (WAS), which are shipped as a component of IBM Tivoli Network Manager. Information about the security vulnerability affecting IBM WebSphere Application Server and Tivoli Integrated Portal have been published in a security bulletin. Struts V1 is used by IBM Tivoli Network Manager, Tivoli

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_open_source_apache_struts_v1_classloader_manipulation_vulnerability_affecting_ibm_tivoli_network_manager_cve_2014_0114?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0114 ,CVE-2014-3054 ,CVE-2014-3055 ,CVE-2014-3056 ,CVE-2014-3057 ,CVE-2014-0224 ,CVE-2014-3026 ,CVE-2014-0221 ,CVE-2014-0195 ,CVE-2014-0198 ,CVE-2010-5298 and CVE-2014-3470.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-07-31

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT