Skip to main content

Collisions in HashTable May Cause DoS Vulnerability


Flash (Alert)


Abstract

Potential Denial of Service (Dos) security exposure when using IBM Rational Build Forge or IBM Rational Automation Framework (RAF), or both Build Forge and RAF, due to JavaHashTable implementation vulnerability.

Content

PROBLEM DESCRIPTION:

Customers who are running Rational Build Forge and/or Rational Automation Framework are vulnerable to a potential performance degradation or Denial of Service (DoS) issue.

USERS AFFECTED:

All users of Rational Build Forge and Rational Automation Framework.

RECOMMENDATION:

For customers using the Apache Tomcat Java Application Server provided by IBM, please refer to the following technotes, and follow the sections for upgrading your Tomcat install.

If you are running Rational Build Forge 7.0.2.7, 7.1.2.2.1, or 7.1.3.0, or older releases in those streams, follow the directions directly.

If you are running Rational Build Forge 7.1.3.1 or 7.1.2.3, install Tomcat version 7.0.23 (or later) instead of the noted 5.5.x as outlined in the note. The instructions are otherwise the same.

Attempting to use Tomcat 7.0.x with Rational Build Forge installs that shipped with Tomcat 5.5.9 will result in a non-functional install.


More information about the vulnerability in Tomcat:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022

For customers using the IBM WebSphere Application Server, refer the following document for more information about the APAR: 4031821 - PM53930: Collisions in HashTable May Cause DoS Vulnerability


Related information

A Japanese translation is available

Cross reference information
Segment Product Component Platform Version Edition
Software Development Rational Automation Framework AIX, Linux, Solaris, Windows 3.0, 3.0.0.1

Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

Rational Build Forge

News


Software version:
7.0.2, 7.0.2.1, 7.0.2.2, 7.0.2.3, 7.0.2.4, 7.0.2.5, 7.0.2.6, 7.0.2.7, 7.1, 7.1.1, 7.1.1.1, 7.1.1.2, 7.1.1.3, 7.1.1.4, 7.1.2, 7.1.2.1, 7.1.2.2, 7.1.2.3, 7.1.3, 7.1.3.1


Operating system(s):
AIX, Linux, Solaris, Windows


Reference #:
1580154


Modified date:
2012-02-07

Translate my page

Content navigation