Security Bulletin
Summary
Apache Tomcat is vulnerable to HTTP request smuggling. Apache Tomcat is used by IBM UrbanCode Build.
Vulnerability Details
CVE-ID: CVE-2014-0227
Description: Apache Tomcat is vulnerable to HTTP request smuggling. A remote attacker could send a specially-crafted request in a malformed chunked header to the Web server to cause multiple processing conflicts on the servers. An attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100751 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Affected Products and Versions
IBM UrbanCode Build 6.1.0 and 6.1.0.1 on all supported platforms.
Remediation/Fixes
Upgrade to IBM UrbanCode Build Fix Pack 2 (6.1.0.2) for 6.1.0 as a new version of Apache is now included in the installer.
Workarounds and Mitigations
- Note: This mitigation is intended for the servers in "Affected Products and Versions" only. It should not be applied on later releases.
- Navigate to <server_install_dir>/opt/tomcat.
- Back up server.xml and tomcat.keystore files from the conf directory.
- Back up the webapps directory.
- Go up a directory to <server_install_dir>/opt and delete the tomcat directory.
- Extract Apache Tomcat 6.0.43 or later into <server_install_dir>/opt and rename the directory to tomcat, if needed.
- In the new tomcat directory, remove the webapps, logs, and temp directories. Remove the RELEASE-NOTES and RUNNING.txt files as well as they are not needed.
- Drop the server.xml and tomcat.keystore files that were backed up earlier into the new conf directory. Overwrite the existing files, if prompted.
- Drop the webapps directory that was backed up earlier into the root of the tomcat directory.
Mitigating HTTP request smuggling through Apache Tomcat
Get Notified about Future Security Bulletins
References
Acknowledgement
None
Change History
* 13 March 2015: Original copy published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
PSIRT # 2818 Record # 50214
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg21698478