Resource management error in Apache CXF - CVE-2019-12406
Published: November 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected software does not restrict the number of message attachments present in a given message. A remote authenticated attacker can craft a message containing a very large number of message attachments and cause a denial of service condition on the target system.
Affected software
z/Transaction Processing Facility ( z/TPF)
IBM Cloud Application Business Insights
Dell Support Assist Enterprise
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Security Guardium
Voice Gateway
How to mitigate CVE-2019-12406
Dell Support Assist Enterprise - update to 4.00.06.00
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache CXF
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Cloud Application Business Insights
- Multiple vulnerabilities in Dell Support Assist Enterprise