Resource management error in HttpComponents Client - CVE-2015-5262

 

Resource management error in HttpComponents Client - CVE-2015-5262

Published: September 20, 2023


Vulnerability identifier: #VU80908
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5262
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

HttpComponents Client
Control Desk
B2B Advanced Communications
Multi-Enterprise Integration Gateway
IBM Engineering Lifecycle Optimization - Publishing
IBM Engineering Systems Design Rhapsody
IBM Tivoli Monitoring
IBM Spectrum Control
NetWorker
IBM Tivoli Application Dependency Discovery Manager
Fedora
Voice Gateway
Cloud Pak for Security (CP4S)
jakarta-commons-httpclient
IBM Rational Asset Manager

How to mitigate CVE-2015-5262

Install updates from vendor's website.

HttpComponents Client - update to 4.3.6
B2B Advanced Communications - update to 1.0.0.8
Multi-Enterprise Integration Gateway - update to 1.0.0.8
Voice Gateway - update to 1.0.8.3
Cloud Pak for Security (CP4S) - update to 1.10.14.0
jakarta-commons-httpclient - addressed in versions 3.1-20.fc21, 3.1-23.fc22, 3.1-23.fc23
IBM Spectrum Control - update to 5.4.10.2
IBM Engineering Lifecycle Optimization - Publishing - addressed in versions 7.0.1.23, 7.0.2.25
IBM Rational Asset Manager - update to 7.5.4.15
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2, 10.0.0.1
NetWorker - addressed in versions 19.9.0.6, 19.10.0.3

External References

Related Security Bulletins