Skip to main content

Security Flash for the RDS Help system


Flash (Alert)


Abstract

Security vulnerabilities have been discovered in the IBM Rational Directory Server (RDS) Help system shipped with the RDS product. When the Help file is opened in Rational Directory Administrator, the 'href' parameter in advanced/deferredView.jsp causes the followng security vulnerabilities: Open Redirect and Cross Site Scripting.

Content

Below are the security vulnerabilitys found in the RDS help (menu 'Help'->'Help' item in RDA window):


Resolution:
This vulnerability affects all versions of RDA (Tivoli) and RDA (Apache). The complete fix for this issue will be delivered through different release cycles:
  • RDA Tivoli: RDS 5.2.0.2 iFix02 is scheduled to be released on 21st June 2012
  • RDA Apache: A fix pack release RDS 5.1.1.2 is planned End of August 2012


WORKAROUND:
In the mean time, this risk can be mitigated by following the below steps.
  1. Download the rds-help.zip file and extract the rds-help.war
    1. FTP: ftp://public.dhe.ibm.com/software/rational/Directory_server/rds-help.zip
    2. HTTP: http://public.dhe.ibm.com/software/rational/Directory_server/rds-help.zip
  2. Stop the WebAccessServer (apache tomcat server)
    Windows:
    <RDS\RDA install location>\WebAccessServer\apache-tomcat-x.0.xx\bin\catalina.bat stop
    Unix:
    <RDS/RDA install location>/WebAccessServer/apache-tomcat-x.0.xx/bin\catalina.sh stop
  3. Go to the location where the war file is located in the RDS/RDA install location.
    Windows:
    <RDS\RDA install location>\WebAccessServer\apache-tomcat-x.0.xx\webapps\
    Unix:
    <RDS/RDA install location>/WebAccessServer/apache-tomcat-x.0.xx/webapps/
  4. Delete/backup the following:
    file: rds-help.war
    Directory: rds-help
  5. Replace the rds-help.war downloaded.
  6. Start the WebAccessServer
    Windows:
    <RDS\RDA install location>\WebAccessServer\Start_RDAWebServer.bat
    Unix:
    <RDS/RDA install location>/WebAccessServer/Start_RDAWebServer.sh
The latest rds-help.war file is now installed which does not have the security vulnerabilitys.

Note: This help file has contents for RDS versions 5.2(Tivoli) and later, and RDS 5.1.1 (Apache) and later


Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

Rational Directory Server

Documentation


Software version:
5.0, 5.1, 5.1.0.1, 5.1.0.2, 5.1.1, 5.1.1.1, 5.2, 5.2.0.1, 5.2.0.2


Operating system(s):
AIX, Linux, Solaris, Windows


Reference #:
1597191


Modified date:
2012-06-20

Translate my page

Content navigation