Boletines de Vulnerabilidades

BM Security Bulletin: Apache Commons FileUpload and Tomcat are vulnerable to a denial of service in FileNet Collaboration Services (formerly known as FileNet Services for Lotus Quickr)


Información sobre el sistema

   
Software afectado IBM

Descripción

Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by the improper handling of Content-Type HTTP header for multipart requests. By sending a specially-crafted request, an attacker could exploit this vulnerability to cause the application to enter into an infinite loop. CVE(s): CVE-2014-0050 Affected product(s) and affected version(s): FileNet Services for Lotus Quickr 1.1 FileNet Collaboration Services 2.0 Note: FileNet Services for Lotus Quickr was renamed

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/bm_security_bulletin_apache_commons_fileupload_and_tomcat_are_vulnerable_to_a_denial_of_service_in_filenet_collaboration_services_formerly_known_as_filenet_services_for_lotus_quickr?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0050 ,CVE-2014-0094 and CVE-2014-0411.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-09-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT