Potential security vulnerability in WAS affecting Asset and Service Mgmt

Flash (Alert)


Abstract

Potential Denial of Service (DoS) security exposure when using Web based applications, such as Asset and Service Management Products, on IBM WebSphere Application Server due to Java HashTable implementation vulnerability (CVE-2012-0193)

Content

Content
VULNERABILITY DETAILS:

CVE ID: CVE-2012-0193


DESCRIPTION:
Customers who have Web based applications are impacted by this vulnerability, which can cause performance or Denial of Service (DoS) issues.

CVSS:
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/72298 for the current score
CVSS Environmental Score*: Undefined
CVSS String: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

VERSIONS AFFECTED:
The following IBM® WebSphere® Application Server Versions for distributed operating systems, IBM i operating systems, and z/OS operating systems are affected:

· Version 8.0 through 8.0.0.2.

· Version 7.0 through 7.0.0.21

· Version 6.1 through 6.1.0.41

· Version 6.0 through 6.0.2.43


IBM supplied WebSphere Application Server versions with the following:

Maximo Asset Management, Maximo Industry Solutions, and Tivoli Asset Management for IT 6.x bundled WebSphere Application Server 6.0.

Maximo Asset Management, Maximo Industry Solutions, Tivoli Asset Management for IT, Tivoli Service Request Manager, and Tivoli Change and Configuration Management Database 7.1 and 7.2 bundled WebSphere Application Server 6.1.

Maximo Asset Management and Maximo Industry Solutions 7.5 bundled WebSphere Application Server 7.0.

Intelligent Building Management 1.1 bundled WebSphere Application Server 7.0.

TRIRIGA Application Platform 3.2 bundled Websphere Application Server 8.0.


REMEDIATION:
Determine the specific version of WebSphere that you have installed, then go to the WebSphere Security Flash for PM53930 to download the appropriate Interim Fix or a Fix Pack containing this APAR. On this page the various Interim Fixes and Fix Packs are separated by the specific WebSphere version. Locate the version of WebSphere that matches your installed version and click the appropriate link to take you to the download page for the fix.

To Determine your WebSphere Version:

1. Access the Administrative Console for WebSphere. Sign into Console.

2. Locate the Welcome Page contains the WebSphere Application Server Version (in this example the version is 6.1.0.35):



(in this example the version is 6.0.2.43)




(in this example the version is 7.0.0.13)


REFERENCES:
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database- IBM WebSphere Application Server Java hash data structure denial of service
CVE-2012-0193

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.

Note:
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Change History
03 Feb 2012 Flash published.

CROSS REFERENCE INFORMATION:

Segment Product Component/Platform Version
Systems and Asset Management Maximo Asset Management All 6.2.0 – 6.2.8

7.1.1.0 – 7.1.1.10

7.5.0.0 – 7.5.0.2

Systems and Asset Management Maximo Asset Management Essentials All 7.1.1.0 – 7.1.1.10

7.5.0.0 – 7.5.0.2

Systems and Asset Management Maximo Asset Management for Energy Optimization All 7.1.0.0 – 7.1.1.0
Systems and Asset Management Maximo for Government All 6.1.0.0

7.1.0.0

7.5.0.0

Systems and Asset Management Maximo for Nuclear Power All 6.3.0

7.1.0.0 – 7.1.1.0

Systems and Asset Management Maximo for Transportation All 6.3.0

7.1.0.0 – 7.1.1.0

7.5.0.0

Systems and Asset Management Maximo for Life Sciences All 6.4.0 – 6.5.0

7.1.0.0 – 7.1.2.0

7.5.00

Systems and Asset Management Maximo for Oil and Gas All 6.3.0 – 6.4.0

7.1.0.0 – 7.1.2.0

7.5.0.0

Systems and Asset Management Maximo for Utilities All 6.3.0

7.1.0.0 – 7.1.2.0

7.5.0.0

Systems and Asset Management Tivoli Service Request Manager All 7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.1.3

Systems and Asset Management Tivoli Asset Management for IT All 6.2.0 – 6.2.8

7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.2.1

Systems and Asset Management Change and Configuration Management Database All 7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.1.2

Systems and Asset Management Intelligent Building Management All 1.1
Systems and Asset Management TRIRIGA Application Platform All 3.2


Cross reference information
Segment Product Component Platform Version Edition
Systems and Asset Management IBM Maximo Asset Management Essentials
Systems and Asset Management IBM Maximo Asset Management for Energy Optimization
Systems and Asset Management IBM Maximo for Government
Systems and Asset Management IBM Maximo for Nuclear Power
Systems and Asset Management IBM Maximo for Life Sciences
Systems and Asset Management IBM Maximo for Transportation
Systems and Asset Management IBM Maximo for Oil and Gas
Systems and Asset Management IBM Maximo for Utilities
Systems and Asset Management Tivoli Service Request Manager
Systems and Asset Management Tivoli Asset Management for IT
Systems and Asset Management Tivoli Change and Configuration Management Database
Systems and Asset Management IBM TRIRIGA Energy Optimization 1.1
Systems and Asset Management IBM TRIRIGA Application Platform 3.2

Rate this page:

(0 users)Average rating

Document information


More support for:

IBM Maximo Asset Management

Software version:

6.1, 6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 7.1, 7.1.1, 7.1.2, 7.2, 7.2.1, 7.5

Operating system(s):

Platform Independent

Reference #:

1578943

Modified date:

2012-02-10

Translate my page

Machine Translation

Content navigation