Potential security vulnerability with IBM WebSphere Application Server

Flash (Alert)


Abstract

Security Bulletin: Asset and Service Management Products - Potential security exposure when using WS-Security, with either JAX-WS or JAX-RPC, resulting in a user gaining elevated privileges (CVE-2011-1377).

Content

VULNERABILITY DETAILS:

CVE ID: CVE-2011-1377

DESCRIPTION:
Websphere Application Server could provide weaker than expected security when using web services security (WS-Security). A user could randomly gain elevated privileges on the provider system. WS-Security may assign the identiy of a previously processed LTPA token to a new inbound LTPA token after authentication. This impacts applications using either JAX-WS or JAX-RPC.

CVSS:
CVSS Base Score: 2.1
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/71319 for the current score
CVSS Environmental Score*: Undefined
CVSS String: (AV:N/AC:H/Au:S/C:N/I:P/A:N)

VERSIONS AFFECTED:

· Websphere Application Server, all platforms, Versions 8.0 through 8.0.0.2, 7.0 through 7.0.0.21, and 6.1 through 6.1.0.41, 6.0.2 through 6.0.2.43.

· Websphere Application Server Feature Pack for Web Services Versions 6.1.0.9 through 6.1.0.39.


IBM supplied Websphere Application Server versions with the following:

Maximo Asset Management, Maximo Industry Solutions, and Tivoli Asset Management for IT 6.x bundled Websphere Application Server 6.0.

Maximo Asset Management, Maximo Industry Solutions, Tivoli Asset Management for IT, Tivoli Service Request Manager, and Tivoli Change and Configuration Management Database 7.1 and 7.2 bundled Websphere Application Server 6.1.

Maximo Asset Management and Maximo Industry Solutions 7.5 bundled Websphere Application Server 7.0.

Smart Cloud Control Desk 7.5 bundled Websphere Application Server 7.0.

Intelligent Building Management 1.1 bundled Websphere Application Server 7.0.

TRIRIGA Energy Optimization 1.1 bundled Websphere Application Server 7.0.

REMEDIATION:
Determine the specific version of WebSphere that you have installed, then go to the Websphere Security Flash for PM43585/PM43792/PM451681 to download the appropriate Interim Fix or a Fix Pack containing this APAR. On this page the various Interim Fixes and Fix Packs are separated by the specific WebSphere version. Locate the version of WebSphere that matches your installed version and click the appropriate link to take you to the download page for the fix.

To Determine your WebSphere Version:

1. Access the Administrative Console for WebSphere. Sign into Console.

2. Locate the Welcome Page contains the WebSphere Application Server Version (in this example the version is 6.1.0.35):



(in this example the version is 6.0.2.43)




(in this example the version is 7.0.0.13)


REFERENCES:
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database
CVE-2011-1377

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.

Note:
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Change History
27 Jul 2012 Flash published.

CROSS REFERENCE INFORMATION:

Segment Product Component/Platform Version
Systems and Asset Management Maximo Asset Management All 6.2.0 – 6.2.8

7.1.1.0 – 7.1.1.10

7.5.0.0 – 7.5.0.3

Systems and Asset Management Maximo Asset Management Essentials All 7.1.1.0 – 7.1.1.10

7.5.0.0 – 7.5.0.3

Systems and Asset Management Maximo Asset Management for Energy Optimization All 7.1.0.0 – 7.1.1.0
Systems and Asset Management Maximo for Government All 6.1.0.0

7.1.0.0

7.5.0.0

Systems and Asset Management Maximo for Nuclear Power All 6.3.0

7.1.0.0 – 7.1.1.0

Systems and Asset Management Maximo for Transportation All 6.3.0

7.1.0.0 – 7.1.1.0

7.5.0.0

Systems and Asset Management Maximo for Life Sciences All 6.4.0 – 6.5.0

7.1.0.0 – 7.1.2.0

7.5.00

Systems and Asset Management Maximo for Oil and Gas All 6.3.0 – 6.4.0

7.1.0.0 – 7.1.2.0

7.5.0.0

Systems and Asset Management Maximo for Utilities All 6.3.0

7.1.0.0 – 7.1.2.0

7.5.0.0

Systems and Asset Management Tivoli Service Request Manager All 7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.1.3

Systems and Asset Management Tivoli Asset Management for IT All 6.2.0 – 6.2.8

7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.2.1

Systems and Asset Management Change and Configuration Management Database All 7.1.0.0 – 7.1.1.10

7.2.0.0 – 7.2.1.2

Systems and Asset Management Smart Cloud Control Desk All 7.5.0.0
Systems and Asset Management Intelligent Building Management All 1.1
Systems and Asset Management TRIRIGA Energy Optimization All 1.1

Cross reference information
Segment Product Component Platform Version Edition
Systems and Asset Management IBM Maximo Asset Management Essentials
Systems and Asset Management IBM Maximo Asset Management for Energy Optimization
Systems and Asset Management IBM Maximo for Government
Systems and Asset Management IBM Maximo for Nuclear Power
Systems and Asset Management IBM Maximo for Transportation
Systems and Asset Management IBM Maximo for Life Sciences
Systems and Asset Management IBM Maximo for Oil and Gas
Systems and Asset Management IBM Maximo for Utilities
Systems and Asset Management Tivoli Service Request Manager
Systems and Asset Management Tivoli Asset Management for IT
Systems and Asset Management Tivoli Change and Configuration Management Database
Systems and Asset Management IBM SmartCloud Control Desk
Systems and Asset Management IBM TRIRIGA Energy Optimization

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

IBM Maximo Asset Management

Software version:

6.2, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 7.1, 7.1.1, 7.2, 7.2.1, 7.5

Operating system(s):

Platform Independent

Reference #:

1606514

Modified date:

2012-07-27

Translate my page

Machine Translation

Content navigation