Information disclosure in Jetty - CVE-2018-12536
Published: July 2, 2018
Vulnerability details
The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to improper handling of queries that do not match the dynamic URL pattern for webapps that use default error handling settings. A remote attacker can send a query that submits malicious input, trigger a java.nio.file.InvalidPathException message, which could allow the attacker to view sensitive information, such as the software installation path.
Affected software
BIG-IP
Cloudera Observability with IBM
BIG-IQ Centralized Management
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
Fedora
Operational Decision Manager
jetty
IBM Cognos Command Center
How to mitigate CVE-2018-12536
IBM Tivoli Netcool/OMNIbus WebGUI - update to 8.1.0.29
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
jetty - addressed in versions 9.4.11-2.v20180605.fc27, 9.4.11-2.v20180605.fc28
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17
External References
Related Security Bulletins
- Multiple vulnerabilities in Eclipse Jetty
- Information disclosure in F5 BIG-IP iControl REST
- Information disclosure in BIG-IQ Centralized Management Restjavad
- Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Operational Decision Manager
- Fedora 28 update for jetty
- Fedora 27 update for jetty
- Multiple vulnerabilities in IBM Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Application Performance Management