Security bulletin: Multiple vulnerabilities in IBM's Netezza WebAdmin 6.0.5, 6.0.8 and 7.0 (CVE-2012-5760, CVE-2012-5761, CVE-2012-5762, CVE-2012-5763, CVE-2012-5940, CVE-2012-5941)

Flash (Alert)


Abstract

Multiple vulnerabilities have been identified in the IBM Netezza WebAdmin application.

Content


VULNERABILITY DETAILS:

CVE ID: CVE-2012-5760

DESCRIPTION:

Elements that could modify a SQL command are not neutralized correctly. The attack will not produce any visible outcome/output in the application but can potentially damage stored data.

CVSS:

CVSS Base Score: 6.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80137 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVE ID: CVE-2012-5761

DESCRIPTION:

User controllable input is not correctly neutralized before it is placed in the output that is served as a web page permitting execution of untrusted scripts.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80138 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5762

DESCRIPTION:

Internet Explorer can be forced to use MHTML protocol which can be manipulated to steal customer session and cookies.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80204 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)


CVE ID: CVE-2012-5763

DESCRIPTION:

The application may fail to verify the authenticity of requests and treat them all as valid. This can result in exposure of data or unintended code execution.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80205 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5941

DESCRIPTION:

User controllable input is not correctly neutralized before it is placed in the output that is served as a web page permitting phishing attempts to steal private information.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80536 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5940

DESCRIPTION:

If SSL support is not enabled, login requests can be intercepted and the details accessed and/or stolen.

CVSS:

CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80535 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N)

AFFECTED VERSIONS/PLATFORMS:

Versions 6.0.5, 6.0.8 and 7.0 of IBM Netezza WebAdmin.

REMEDIATION:

Fix(es):

Version 7.0: Install patch version 7.0 P2 which can be obtained via Fix Central
(http://www-933.ibm.com/support/fixcentral)

Workaround(s):

CVE-2012-5940: Install IBM Netezza WebAdmin 7.0 with SSL support.

Mitigation(s):

None known.

REFERENCES:

· Complete CVSS Guide
· On-line Calculator V2
· X-Force Vulnerability Database
· CVE-2012-5760
· CVE-2012-5761
· CVE-2012-5762
· CVE-2012-5763
· CVE-2012-5941
· CVE-2012-5940

RELATED INFORMATION:

· IBM Secure Engineering Web Portal
· IBM Product Security Incident Response Blog

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.


Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Rate this page:

(0 users)Average rating

Document information


More support for:

PureData System for Analytics

Software version:

1.0.0

Operating system(s):

Platform Independent

Reference #:

1624568

Modified date:

2014-04-04

Translate my page

Machine Translation

Content navigation