IBM Support

JR60619: FILE UPLOAD JSP FILES ARE DIRECTLY ACCESSIBLE FROM THE URL: HTTP://<SERVER IP>:7507/CCD_CONNECTIVITY/IMAGE_UPLOADER.JSP

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • File upload jsp files are directly accessible from the URL:
    http://<Server
    Ip>:7507/ccd_connectivity/image_uploader.jsp.
     In such scenario an adversary can upload malicious files to
    the web server through the upload option.
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:                                              *
    * All Master Data Management Collaboration Server              *
    * implementations are affected by this issue.                  *
    ****************************************************************
    * PROBLEM DESCRIPTION:                                         *
    * File upload jsp files are directly accessible from the URL:  *
    * http://<Server                                               *
    * Ip>:7507/ccd_connectivity/image_uploader.jsp.                *
    *  In such scenario an adversary can upload malicious files to *
    * the web server through the upload option.                    *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    

Problem conclusion

  • Customers facing the issue reported by this APAR apply Master
    Data Management Collaboration Server version MDMCE 11.6.0-FP012
    IF002 or later to gain resolution to this problem.
    

Temporary fix

Comments

APAR Information

  • APAR number

    JR60619

  • Reported component name

    MDM SERVER FOR

  • Reported component ID

    5724V5100

  • Reported release

    B60

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2019-01-30

  • Closed date

    2019-07-04

  • Last modified date

    2019-07-04

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    MDM SERVER FOR

  • Fixed component ID

    5724V5100

Applicable component levels

[{"Business Unit":{"code":"BU053","label":"Cloud \u0026 Data Platform"},"Product":{"code":"SS2U2U","label":"InfoSphere Master Data Management Collaboration = Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"B60"}]

Document Information

Modified date:
08 September 2023