Symantec IGA

 View Only

Important notification regarding CVE-2020-1938 (Ghostcat)

By Itamar Budin posted Mar 31, 2020 10:53 AM

  
Hi

This notice is to alert you to the availability of patches and instructions regarding the Ghostcat vulnerability (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1938 and https://nvd.nist.gov/vuln/detail/CVE-2020-1938).   

This vulnerability is rated at 9.8 Critical Severity.  Please give this high attention.


Symantec IGA uses Apache Tomcat in the Virtual Appliance and makes use of the Apache JServ Protocol (AJP).  

Patches and deployment instructions for the following versions of these Virtual Appliance components are being made available via these location:

14.3:

14.2:

14.1:

In addition, our report server solution, which is based on TIBCO JasperSoft is also utilizing Apach Tomact. For more information on how to mitigate this CVE, please follow the instructions on this link:

https://community.jaspersoft.com/wiki/fixing-tomcat-cve-2020-1938-tibco-jasperreporrts-server


Note that the method to exploit this vulnerability is not described in the CVE detail. However, in order to provide a higher level of assurance to our customers we are providing these patches. 

If you have questions please contact Broadcom Support:

https://www.broadcom.com/support/services-support/ca-support/contact-support?intcmp=footernav

Thanks in advance

Itamar Budin

Product Management Lead  - Identity Governance & Administration | Symantec Software Division

Symantec, A Broadcom Company


1 comment
26 views

Permalink