Boletines de Vulnerabilidades

IBM Security Bulletin: An Apache Struts security vulnerability affects the Tivoli Integrated Portal component of the Tivoli Storage Manager Administration Center (CVE-2014-0114)


Información sobre el sistema

   
Software afectado IBM

Descripción

The IBM Tivoli Storage Manager Administration Center is shipped with IBM Tivoli Integrated Portal and IBM embedded WebSphere (eWAS) as components. There is a ClassLoader manipulation vulnerability in the Apache Struts levels that are used by Tivoli Integrated Portal and eWAS (CVE-2014-0114). A critical patch update was released for Tivoli Integrated Portal. The update contains a fix that applies to the Administration Center. CVE(s): CVE-2014-0114 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_an_apache_struts_security_vulnerability_affects_the_tivoli_integrated_portal_component_of_the_tivoli_storage_manager_administration_center_cve_2014_0114?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0114 ,CVE-2014-0907 ,CVE-2013-6335 ,CVE-2014-0076 ,CVE-2014-0195 ,CVE-2014-0224 ,CVE-2014-0221 ,CVE-2014-3470 and CVE-2014-0963.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-25

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT