IBM Support

Potential security exposure within Information Server after installing an application server update PM44303

Flashes (Alerts)


Abstract

Potential security exposure within Information Server after installing an application server update PM44303

Content


The affected WebSphere Application Server releases have the potential for an authenticated user to bypass security restrictions, caused by an error when validating user credentials. This could allow a user to gain unauthorized administrative access to an application and potentially gain access to confidential and critical customer data.

InfoSphere Information Server 8.5 or 8.7 releases could be affected if you have applied Interim Fix for PM44303, or one of the following WebSphere Application Server Fix Packs containing PM44303:

  • Version 6.1.0.43
  • Version 7.0.0.21 through 7.0.0.23


More detailed information regarding this security issue is available in technote 1609067 for WebSphere Application Server (WAS), located in the related information section below.



Note:

The Information Server 8.0.1 and Information Server 8.1 releases are not affected, as both of these depend on WebSphere Application Server 6.0.2.x releases.


Step 1. Determine your WebSphere Application Server Version

The first few lines in the SystemOut.log file will tell you the exact version of WebSphere Application Server (WAS) that is being used, as show in the sample given here:

************ Start Display Current Environment ************
WebSphere Platform 7.0.0.17 [ND 7.0.0.17 cf171115.15] running with process name TestMachineNode01Cell\TestMachineNode01\server1 and process id 1556

In this sample above, the exact version is 7.0.0.17. The location of this file will vary based on the platform and choice of installation directory by the user. The default value will usually be something similar to:

/opt/IBM/WebSphere/AppServer/profiles/default/logs/server1/


Step 2. Locate the version in the WAS Technote 1609067 and then choose a fix method

You can either install the individual APAR fixes which are identified in the technote, or alternatively you can install the necessary WebSphere Application Server fixpack which contains the fix.

Related Information

[{"Product":{"code":"SSZJPZ","label":"IBM InfoSphere Information Server"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.7;8.5","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
25 September 2022

UID

swg21611059