Security Bulletin
Summary
The IBM InfoSphere Balanced Warehouse C3000 and C4000 for Windows and IBM Smart Analytics System 1050 and 2050 for Windows ship with Apache HTTP Server which contains known security vulnerabilities.
Vulnerability Details
CVE-ID: CVE-2014-0098
DESCRIPTION: Apache HTTP Server is vulnerable to a denial of service, caused by an error in the mod_log_config module when logging a cookie with an unassigned value. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the service to crash.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91879 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVE-ID: CVE-2013-6438
DESCRIPTION: Apache HTTP Server is vulnerable to a denial of service, caused by an error in the mod_dav module when tracking the length of CDATA that includes removing white space. By sending a specially-crafted DAV WRITE request, a remote attacker could exploit this vulnerability to cause the service to stop responding.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/90878 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Affected Products and Versions
IBM InfoSphere Balanced Warehouse C3000 for Windows
IBM InfoSphere Balanced Warehouse C4000 for Windows
IBM Smart Analytics System 1050 for Windows
IBM Smart Analytics System 2050 for Windows
Remediation/Fixes
For each affected component in the table, download the recommended fix, and install using the link in the Installation instructions column.
For more information about IBM IDs, see the Help and FAQ.
| Product | Affected Component | Recommended Fix | Download Link | Installation instructions |
| IBM InfoSphere Balanced Warehouse C3000 for Windows IBM InfoSphere Balanced Warehouse C4000 for Windows IBM Smart Analytics System 1050 for Windows IBM Smart Analytics System 2050 for Windows | Apache HTTP Server 2.2 | Update Apache HTTP Server to 2.2.27 | Apache HTTP Server 2.2.27 | Updating Apache HTTP Server in an IBM InfoSphere Balanced Warehouse and IBM Smart Analytics System environment |
Contact IBM Support:
In the United States and Canada dial 1-800-IBM-SERV
View the support contacts for other countries outside of the United States.
Electronically open a Service Request with IBM Support.
Get Notified about Future Security Bulletins
References
Change History
July 16, 2014: Original version published.
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
16 June 2018
UID
swg21674621