Improper input validation in Oracle Transportation Management - CVE-2012-0881

 

Improper input validation in Oracle Transportation Management - CVE-2012-0881

Published: July 28, 2021


Vulnerability identifier: #VU55416
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0881
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the UI Infrastructure (Apache Xerces2 Java Parser) component in Oracle Transportation Management. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle Transportation Management
IBM Sterling Order Management
Tivoli Network Manager IP Edition
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Call Center for Commerce
IBM Business Automation Workflow
App Connect Enterprise Certified Container
IBM SPSS Modeler
Atlas eDiscovery Process Management
IBM Sterling B2B Integrator
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Cloud Pak for Business Automation
IBM Content Navigator
IBM Tivoli Application Dependency Discovery Manager
IBM Cloud Pak System
IBM Case Manager
Jazz Reporting Service
Jazz Foundation
Operational Decision Manager

How to mitigate CVE-2012-0881

Install updates from vendor's website.

IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
IBM Case Manager - update to 5.3.3-IF011
Atlas eDiscovery Process Management - update to 6.0.3.9.7
IBM Sterling B2B Integrator - addressed in versions 6.1.2.5, 6.2.0.1
Jazz Reporting Service - update to 7.0.2 iFix022
Jazz Foundation - update to 7.0.2.0.27
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.14, 8.1.4.0.16
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6

External References

Related Security Bulletins