Apache POI < 3.17 Multiple DoS Vulnerabilities
search cancel

Apache POI < 3.17 Multiple DoS Vulnerabilities

book

Article ID: 266778

calendar_today

Updated On:

Products

CA Application Performance Management (APM / Wily / Introscope)

Issue/Introduction

Security findings on  Apache POI < 3.17 Multiple DoS Vulnerabilities on Introscope product.

What is required to remediate this finding? 

Path : /app/introscope/com.wily.apm.tess/WebContent/WEB-INF/lib/displaytag-export-poi-1.2.jar Installed version : 1.2 Fixed version : 3.17

Path : /app/introscope/product/enterprisemanager/configuration/org.eclipse.osgi/bundles/122/1/.cp/lib/poi-3.16.jar Installed version : 3.16 Fixed version : 3.17

Path : /app/introscope/product/enterprisemanager/configuration/org.eclipse.osgi/bundles/122/1/.cp/lib/poi-excelant-3.16.jar Installed version : 3.16 Fixed version : 3.17

Path : /app/introscope/product/enterprisemanager/configuration/org.eclipse.osgi/bundles/122/1/.cp/lib/poi-ooxml-3.16.jar Installed version : 3.16 Fixed version : 3.17

Path : /app/introscope/product/enterprisemanager/configuration/org.eclipse.osgi/bundles/122/1/.cp/lib/poi-scratchpad-3.16.jar Installed version : 3.16 Fixed version : 3.17

Path : /app/introscope/product/enterprisemanager/configuration/org.eclipse.osgi/bundles/49/1/.cp/WebContent/WEB-INF/lib/displaytag-export-poi-1.2.jar Installed version : 1.2 Fixed version : 3.17

Environment

Release : APM 10.7 SP3

Resolution

Since you are not using CEM or Team Center, please do the following to mitigate this issue:

1.  Stop EM
2.  Make a backup copy of file /opt/wily/Introscope10.7/EM/com.wily.apm.tess/WebContent/WEB-INF/lib/displaytag-export-poi-1.2.jar and delete the file from its current location
3.  Open the IntroscopeEnterpriseManager.properties file in <EM_HOME>/config folder and add/edit below property:

introscope.apm.feature.enabled=false

4.  Clear product cache.
5.  Delete the entire content [all files and directories] of <EM-Home>/work
6.  Delete the entire content [all files and directories] of ./configuration folder except settings and config.ini (DO NOT delete config.ini and settings) 
path: <EM-Home>/product/enterprisemanager/configuration
7.  Delete all files at <EM-Home>/logs
8.  Start EM