Skip to main content

Potential security exposure within Information Server after installing an application server update PM44303


Flash (Alert)


Abstract

Potential security exposure within Information Server after installing an application server update PM44303

Content

The affected WebSphere Application Server releases have the potential for an authenticated user to bypass security restrictions, caused by an error when validating user credentials. This could allow a user to gain unauthorized administrative access to an application and potentially gain access to confidential and critical customer data.

InfoSphere Information Server 8.5 or 8.7 releases could be affected if you have applied Interim Fix for PM44303, or one of the following WebSphere Application Server Fix Packs containing PM44303:

  • Version 6.1.0.43
  • Version 7.0.0.21 through 7.0.0.23


More detailed information regarding this security issue is available in technote 1609067 for WebSphere Application Server (WAS), located in the related information section below.



Note:

The Information Server 8.0.1 and Information Server 8.1 releases are not affected, as both of these depend on WebSphere Application Server 6.0.2.x releases.


Step 1. Determine your WebSphere Application Server Version

The first few lines in the SystemOut.log file will tell you the exact version of WebSphere Application Server (WAS) that is being used, as show in the sample given here:

************ Start Display Current Environment ************
WebSphere Platform 7.0.0.17 [ND 7.0.0.17 cf171115.15] running with process name TestMachineNode01Cell\TestMachineNode01\server1 and process id 1556

In this sample above, the exact version is 7.0.0.17. The location of this file will vary based on the platform and choice of installation directory by the user. The default value will usually be something similar to:

/opt/IBM/WebSphere/AppServer/profiles/default/logs/server1/


Step 2. Locate the version in the WAS Technote 1609067 and then choose a fix method

You can either install the individual APAR fixes which are identified in the technote, or alternatively you can install the necessary WebSphere Application Server fixpack which contains the fix.

Related information

WebSphere Technote Flash 1609067

Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

InfoSphere Information Server


Software version:
8.5, 8.7


Operating system(s):
AIX, HP-UX, Linux, Solaris, Windows


Reference #:
1611059


Modified date:
2012-10-04

Translate my page

Content navigation