Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Tivoli Monitoring (CVE-2014-0114,CVE-2014-0964)


Información sobre el sistema

   
Software afectado IBM

Descripción

The following security issues have been identified in WebSphere Application Server included as part of IBM Tivoli Monitoring portal server. There is a classloader manipulation vulnerability in the Apache Struts 1 that is used by IBM WebSphere Application Server Administrative Console. There is a potential denial of service with WebSphere Application Server when running a Heartbleed scanning tool. CVE(s): CVE-2014-0114 and CVE-2014-0964 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_monitoring_cve_2014_0114_cve_2014_0964?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0114 ,CVE-2014-0964 ,CVE-2014-3466 ,CVE-2014-0453 ,CVE-2014-0460 ,CVE-2014-0878 and CVE-2014-2828.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-08

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT