SB2022072205 - Denial of service in IBM Rational Build Forge
Published: July 22, 2022 Updated: October 25, 2024
Security Bulletin ID
SB2022072205
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Data Handling (CVE-ID: CVE-2022-29885)
The vulnerability allows a remote attacker to perform DoS attack.
The vulnerability exists due to an error in documentation for the EncryptInterceptor, which incorrectly stated that it enabled Tomcat clustering to run over an untrusted network. A remote attacker can perform a denial of service attack against the exposed EncryptInterceptor.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-rational-build-forge-is-vulnerable-to-a-denial-of-service-due-to-use-of-apache-tomcat-server-cve-2022-29885/"
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-rational-build-forge-is-vulnerable-to-a-denial-of-service-due-to-use-of-apache-tomcat-server-cve-2022-29885/</a><br><a
- https://www.ibm.com/support/pages/node/6606239"
- https://www.ibm.com/support/pages/node/6606239</a><br><br><br></p>