IBM disclosed that the Rational Test Control Panel component in Rational Test Workbench and Rational Test Virtualization Server is affected by three Apache Tomcat vulnerabilities: HTTP request smuggling (CVE-2013-4286), remote denial of service (CVE-2013-4322), and arbitrary-file-read information disclosure (CVE-2013-4590). The latter is an XML external entity (XXE) flaw that can expose Tomcat internal information when an attacker can deploy or leverage an untrusted web application containing crafted XML with external entity declarations.
Affected customers should apply IBM's Tomcat 7.0.52 fix packages; IBM listed no workarounds or mitigations. Rational Test Control Panel version 8.5.1 and later is not affected because it no longer uses Apache Tomcat.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2013-4590 was updated.
Fedora pushed tomcat-7.0.52-1.fc20 to the Fedora 20 stable repository to address CVE-2013-4322, the Apache Tomcat chunked-transfer denial-of-service flaw. Red Hat also issued remediation advisories for affected RHEL and JBoss Enterprise Web Server products.
IBM disclosed that Rational Test Workbench and Rational Test Virtualization Server Rational Test Control Panel versions 8.0 through 8.5.0.2 were affected by CVE-2013-4590 and two other Apache Tomcat flaws. IBM directed customers to apply Tomcat 7.0.52 remediation packages; versions 8.5.1 and later were unaffected because they no longer used Tomcat.
Red Hat issued RHSA-2014:0429 to remediate CVE-2013-4322 in the Red Hat Enterprise Linux 6 tomcat6 package. The flaw allowed unauthenticated remote attackers to consume bandwidth, CPU, and memory through excessively long chunked HTTP requests.
CVE-2013-4322 was published for an Apache Tomcat denial-of-service vulnerability in HTTP chunked-transfer coding. The incomplete fix for CVE-2012-3544 allowed remote attackers to exhaust resources with excessive chunked data or whitespace in trailer-field header values.
CVE-2014-0033 was published describing a session-fixation vulnerability in Apache Tomcat 6.0.33 through 6.0.37. The flaw allowed a remote attacker to supply an attacker-controlled session ID through a crafted URL because the disableURLRewriting setting was not honored.
CVE-2013-4590 was published describing an XML external entity vulnerability in Apache Tomcat that could disclose internal information when an attacker could deploy or leverage an untrusted application containing a crafted XML document.
IBM X-Force reported CVE-2013-4286, an Apache Tomcat HTTP request-smuggling flaw caused by incomplete handling of requests containing both Transfer-Encoding: chunked and Content-Length headers. Apache recommended upgrading to Tomcat 6.0.39, 7.0.47, 8.0.0-RC3, or later; exploitation could enable cache poisoning, WAF bypass, and cross-site scripting.
Red Hat issued CVE-2013-4322 updates for Red Hat Enterprise Linux 7 (RHSA-2014:0686) and JBoss Enterprise Web Server 2.0.1 and JBEWS 2 deployments on RHEL 5 and RHEL 6 (RHSA-2014:0525, RHSA-2014:0526, RHSA-2014:0527, and RHSA-2014:0528). The updates addressed the Tomcat chunked-transfer denial-of-service flaw caused by the incomplete CVE-2012-3544 fix.
Red Hat issued updates addressing CVE-2013-4286 for Enterprise Linux 6 and 7 and numerous JBoss products, including Enterprise Application Platform, BRMS, BPM Suite, Data Grid, Data Virtualization, Operations Network, Enterprise Web Server, Fuse Service Works, and Portal. The fixes addressed Tomcat request-framing ambiguity involving Content-Length and chunked-transfer headers or multiple Content-Length headers.
IBM X-Force documented CVE-2013-4322 as an unauthenticated remote denial-of-service vulnerability in Apache Tomcat's processing of HTTP chunked transfer coding, caused by incomplete handling of large aggregate chunked data or whitespace in header values. Apache recommended upgrades to Tomcat 6.0.39, 7.0.50, 8.0.0-RC10, or later.
IBM disclosed that QRadar SIEM 7.1 MR2 and 7.2 MR2 contain Apache Tomcat vulnerabilities CVE-2013-4286, CVE-2014-0033, CVE-2013-4322, and CVE-2013-4590. IBM recommended Patch 7 for QRadar 7.1 MR2 and Patch 3 for QRadar 7.2 MR2, with no workarounds provided.
Red Hat released JBoss Enterprise Application Platform 6.2.2, fixing CVE-2013-4286 in JBoss Web and CVE-2014-0093, which could improperly grant deployed applications java.security.AllPermission. Red Hat advised EAP 6.2 users to install the update and restart JBoss for the changes to take effect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
exchange.xforce.ibmcloud.com
Open sourceexchange.xforce.ibmcloud.com
Open sourceexchange.xforce.ibmcloud.com
Open sourcebugzilla.redhat.com
Open sourcesvn.apache.org
Open sourcesvn.apache.org
Open sourcesvn.apache.org
Open sourcesvn.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.