Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

Vulnerabilities found under RQM v2.0.1.1

Hi

Is there any know vulnerabilities reported with reference to RQM v2.0.1.1 and Apache Tomcat that is shipped with RQM.

Following are a few vulnerabilities that are found under RQM after a scan process done.

1) X.509 Server Certificate Is Invalid/Expired
2) Apache Tomcat default installation/welcome page installed
3) MD5-based Signature in TLS/SSL Server X.509 Certificate

Thanks




0 votes

Comments

Inputs if any on the above question, please ??

1) buy a signed SSL certificate or if your company permits, use self-signed
2) Delete all the directories under webapps (except the jazz, jazz.war)
3) Edit the connector definition in conf/server.xml with a ciphers= entry.  e.g.

ciphers="TLS_DHE_RSA_WITH_AES_12
8_CBC_SHA,SSL_RSA_WITH_RC4_128_MD5,SSL_RSA_WITH_RC4_128_SHA,TLS_RSA_WITH_AES_128
_CBC_SHA,SSL_RSA_WITH_3DES_EDE_CBC_SHA"



One answer

Permanent link
 Rajesh,
You can identify the version of Tomcat you have installed by running the version command from within the "...server\tomcat\bin" folder
Once you have the version you can perform a search on "tomcat.apache.org" for the vulnerabilities for that specific version


Ara
 

0 votes

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details

Question asked: Mar 15 '13, 3:07 a.m.

Question was seen: 4,121 times

Last updated: Mar 18 '13, 4:20 p.m.

Confirmation Cancel Confirm