Security Bulletin: Websphere denial-of-service vulnerability affects IBM Control Center (CVE-2019-12402)

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Affected product(s) and affected version(s):

Affected Product(s)

Version(s)

IBM Control Center

6.0.0.0 through 6.0.0.2 iFix08

IBM Control Center

6.1.0.0 through 6.1.2.1 iFix01

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1284568

The post Security Bulletin: Websphere denial-of-service vulnerability affects IBM Control Center (CVE-2019-12402) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2O6BU6C