Security Bulletin: IBM Tivoli NetView for z/OS - Gain Permissions Vulnerability (CVE-2012-5951)

Flash (Alert)


Abstract

An otherwise normal Unix System Services (USS) user can assume the elevated security setting of NetView for z/OS to execute an arbitrary program at that elevated security level.

Content

VULNERABILITY DETAILS:

CVE ID: CVE-2012-5951

DESCRIPTION: An otherwise normal Unix System Services(USS) user can assume the elevated security setting of NetView for z/OS to execute an arbitrary program at that elevated security level.

CVSS:


CVSS Base Score: 7.2
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80643 for the current score
CVSS Environmental Score*: Undefined
CVSS String: (AV:L/AC:L/Au:N/C:C/I:C/A:C)


AFFECTED PLATFORMS:

  • Affected releases: 1.4, 5.1 through 5.4 & 6.1
  • Releases/systems/configurations NOT affected: none

REMEDIATION: See table below for the appropriate PTF fix.
Fix*
Original Fix (PE)
VRMF
zNetView Vulnerability APAR /
PE fix APAR
Download URL
PTF UA67653
PTF UA67533
6.1
OA41061 / OA41132
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67653
PTF UA67656
PTF UA67555
5.4
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67656
PTF UA67660
PTF UA67559
5.3 Japanese
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67660
PTF UA67659
PTF UA67558
5.3 English
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67659
PTF UA67658
PTF UA67557
5.2 Japanese
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67658
PTF UA57657
PTF UA67556
5.2 English
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67657
PTF UA57662
PTF UA67561
5.1 Japanese
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67662
PTF UA67661
PTF UA67560
5.1 English
OA41060 / OA41127
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67661
PTF UA67655
PTF UA67554
1.4 Japanese
OA41059 / OA41131
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67655
PTF UA67654
PTF UA67553
1.4 English
OA41059 / OA41131
https://www14.software.ibm.com/webapp/set2/ordermedia/shopCart?ptfs=UA67654

Note concerning the PE status of the original fixes (PTFs): See corresponding PE fix APAR for details.

Workaround/Mitigation(s):
None

REFERENCES:
Any additional links, including related advisories (issued by IBM or other vendors), links to CVSS v2 Guide, CVSS calculator, X-Force database entry, and CVE entry link for the listed vulnerability or vulnerabilities.
RELATED INFORMATION:


ACKNOWLEDGEMENT:
None


CHANGE HISTORY:
  • December 21, 2012 Advisory Flash Created
  • January 14, 2013 Updated to include PE information

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.


Note:
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.


Product Alias/Synonym

zNetView

Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

Tivoli NetView for z/OS

Software version:

1.4, 5.1, 5.2, 5.3, 5.4, V6R1

Operating system(s):

z/OS

Software edition:

All Editions

Reference #:

1621163

Modified date:

2013-03-06

Translate my page

Machine Translation

Content navigation