Skip to main content

Security Bulletin: Rational Change client side deployments affected by vulnerabilities if IBM JRE is installed by end user (CVE-2012-4820, CVE-2012-4821, CVE-2012-4822, CVE-2012-4823)


Flash (Alert)


Abstract

These vulnerabilities are only applicable to client-side IBM Java deployments where untrusted code may be executed (such as Java applets running in a web browser). Server applications such as WebSphere Application Server are not vulnerable.
Rational Change uses a Java applet as part of its integration with Rational Synergy (to launch Rational Synergy dialogs, such as history and compare, from show forms and reports). To run these applets, a Rational Change client (Browser) uses whichever Java is registered or installed in the end user’s systems and not the IBM JRE bundled with Synergy. Therefore customers would have this problem only if the IBM JRE is manually installed and registered on their client systems. The remedy here is to upgrade the IBM JRE to Java 6 SR12 on the client machines.

Content

VULNERABILITY DETAILS:

CVE IDs: CVE-2012-4820, CVE-2012-4821, CVE-2012-4822, CVE-2012-4823

DESCRIPTION:
There are a number of vulnerabilities in the IBM JAVA SDK versions that affect various components (ORB, XML and JMX). Some of the issues need to be combined in sequence to achieve an exploit. This occurs when the affected JRE is installed as the system JRE.

For example, this can occur when a JRE is running Java applets or Web Start applications.

CVEID: CVE-2012-4820
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/78764 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2012-4821
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/78765 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2012-4822
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/78766 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVEID: CVE-2012-4823
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/78767 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

AFFECTED PRODUCTS AND VERSIONS:
Any supported Rational Change client platform

REMEDIATION:
Upgrade IBM JRE to Java 6 SR12 or later on the client machines or switch to the Oracle JRE. You can download IBM Java 6 SR 12 from http://www.ibm.com/developerworks/java/jdk/index.html.
Windows clients will need to use the Oracle JRE.

WORKAROUND(S):
None. Update JRE.

MITIGATION(S):
Do not visit untrusted web sites while the browser has a vulnerable JRE enabled.


REFERENCES:
· Complete CVSS Guide
· On-line Calculator V2
· CVE-2011-4820
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/78764
· CVE-2011-4821
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/78765
· CVE-2011-4822
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/78766
· CVE-2011-4823
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/78767


RELATED INFORMATION:
http://seclists.org/bugtraq/2012/Sep/38

ACKNOWLEDGEMENT
The vulnerability was reported to IBM by Adam Gowdiak of Security Explorations.

CHANGE HISTORY
None

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the References section of this Flash.


Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.


Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

Rational Change

General Information


Software version:
5.2.0.7, 5.3.0.4


Operating system(s):
AIX, Linux, Solaris, Windows


Reference #:
1615800


Modified date:
2012-11-13

Translate my page

Content navigation