IBM Support

Security Bulletin: IBM InfoSphere Balanced Warehouse C3000, C4000, IBM Smart Analytics System 1050, and 2050 are affected by the following Apache Tomcat vulnerabilities: CVE-2014-0098 and CVE-2013-6438

Created by David Tam on
Published URL:
https://www.ibm.com/support/pages/node/511787
511787

Security Bulletin


Summary

The IBM InfoSphere Balanced Warehouse C3000 and C4000 for Windows and IBM Smart Analytics System 1050 and 2050 for Windows ship with Apache HTTP Server which contains known security vulnerabilities.

Vulnerability Details


CVE-ID: CVE-2014-0098

DESCRIPTION: Apache HTTP Server is vulnerable to a denial of service, caused by an error in the mod_log_config module when logging a cookie with an unassigned value. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the service to crash.

CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91879 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVE-ID: CVE-2013-6438

DESCRIPTION: Apache HTTP Server is vulnerable to a denial of service, caused by an error in the mod_dav module when tracking the length of CDATA that includes removing white space. By sending a specially-crafted DAV WRITE request, a remote attacker could exploit this vulnerability to cause the service to stop responding.

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/90878 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

Affected Products and Versions

IBM InfoSphere Balanced Warehouse C3000 for Windows
IBM InfoSphere Balanced Warehouse C4000 for Windows
IBM Smart Analytics System 1050 for Windows
IBM Smart Analytics System 2050 for Windows

Remediation/Fixes

For each affected component in the table, download the recommended fix, and install using the link in the Installation instructions column.

For more information about IBM IDs, see the Help and FAQ.

ProductAffected ComponentRecommended FixDownload LinkInstallation instructions
IBM InfoSphere Balanced Warehouse C3000 for Windows
IBM InfoSphere Balanced Warehouse C4000 for Windows
IBM Smart Analytics System 1050 for Windows
IBM Smart Analytics System 2050 for Windows
Apache HTTP Server 2.2Update Apache HTTP Server to 2.2.27Apache HTTP Server 2.2.27Updating Apache HTTP Server in an IBM InfoSphere Balanced Warehouse and IBM Smart Analytics System environment

Contact IBM Support:
In the United States and Canada dial 1-800-IBM-SERV
View the support contacts for other countries outside of the United States.
Electronically open a Service Request with IBM Support.

Get Notified about Future Security Bulletins

References

Off

Change History

July 16, 2014: Original version published.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSFVXC","label":"InfoSphere Balanced Warehouse"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Balanced Warehouse C Class - C3000","Platform":[{"code":"PF033","label":"Windows"}],"Version":"9.7","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}},{"Product":{"code":"SSFVXC","label":"InfoSphere Balanced Warehouse"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Balanced Warehouse C Class - C4000","Platform":[{"code":"PF033","label":"Windows"}],"Version":"9.7","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}},{"Product":{"code":"SSKT3D","label":"IBM Smart Analytics System"},"Business Unit":{"code":"BU050","label":"BU NOT IDENTIFIED"},"Component":"IBM Smart Analytics System 1050","Platform":[{"code":"PF033","label":"Windows"}],"Version":"9.7","Edition":"","Line of Business":{"code":"","label":""}},{"Product":{"code":"SSKT3D","label":"IBM Smart Analytics System"},"Business Unit":{"code":"BU050","label":"BU NOT IDENTIFIED"},"Component":"IBM Smart Analytics System 2050","Platform":[{"code":"PF033","label":"Windows"}],"Version":"9.7","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
16 June 2018

UID

swg21674621