Security Bulletin: WebSphere Portal vulnerability to HTTP response splitting if home substitution enabled (CVE-2013-2950)

Flash (Alert)


Abstract

When home substitution is enabled (disabled by default), WebSphere Portal becomes vulnerable for HTTP Response Splitting.

Content

VULNERABILITY DETAILS:


DESCRIPTION:
When home substitution is enabled (disabled by default, parameter is uri.home.substitution), Portal becomes vulnerable for HTTP Response Splitting.
An attacker can exploit this to set arbitrary content in the second response, giving control over the appearance of the content rendered.


CVEID: CVE-2013-2950
CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83618 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/AU:S/C:N/I:P/A:N)


AFFECTED PRODUCTS AND VERSIONS:
WebSphere Portal Version 6.1.0.x
WebSphere Portal Version 6.1.5.x
WebSphere Portal Version 7.0.0.x
WebSphere Portal Version 8.0.0.x


REMEDIATION:
APAR PM85071 addresses the issue and is included in the following cummulative fixpacks.
For WebSphere Portal 6.1.0.3 and later APAR PM85071 is included in CF26
For WebSphere Portal 7.0.0.2 APAR PM85071 is included in CF21

Fix* APAR How to acquire fix
WebSphere Portal 6.1.0.3/6.1.5 Cumulative Fix 26 or higher
      PM85071
Cumulative fixes for WebSphere Portal 6.1.0.x/6.1.5.x: http://www.ibm.com/support/docview.wss?uid=swg24023835
WebSphere Portal 6.1.0.4/6.1.5.1 Cumulative Fix 26 or higher
      PM85071
Cumulative fixes for WebSphere Portal 6.1.0.x/6.1.5.x: http://www.ibm.com/support/docview.wss?uid=swg24023835
WebSphere Portal 6.1.0.5/6.1.5.2 Cumulative Fix 26 or higher
      PM85071
Cumulative fixes for WebSphere Portal 6.1.0.x/6.1.5.x: http://www.ibm.com/support/docview.wss?uid=swg24023835
WebSphere Portal 6.1.0.6/6.1.5.3 Cumulative Fix 26 or higher
      PM85071
Cumulative fixes for WebSphere Portal 6.1.0.x/6.1.5.x: http://www.ibm.com/support/docview.wss?uid=swg24023835
WebSphere Portal 7.0.0.2 Cumulative Fix 21 or higher
      PM85071
Combined Cumulative fixes for WebSphere Portal 7.0.0.2: http://www.ibm.com/support/docview.wss?uid=swg24029452
WebSphere Portal 8.0.0 Cumulative Fix 5 or higher
      PM85071
Combined Cumulative Fixes for WebSphere Portal 8.0.0.0: http://www.ibm.com/support/docview.wss?uid=swg24033155
WebSphere Portal 8.0.0.1 Cumulative Fix 5 or higher
      PM85071
Combined Cumulative Fixes for WebSphere Portal 8.0.0.1: http://www.ibm.com/support/docview.wss?uid=swg24034497
None For WebSphere Portal 6.1.0.1, 6.1.0.2, 7.0.0 and 7.0.0.1 contact support.



Workaround(s):
Disable home substitution to work around the problem. The parameter is uri.home.substitution, see the Information Center of WebSphere Portal:
v8: http://www.lotus.com/ldd/portalwiki.nsf/dx/Configuration_Service_wp8
v7: http://www.lotus.com/ldd/portalwiki.nsf/dx/Portal_configuration_services_wp7
v6.1: http://publib.boulder.ibm.com/infocenter/wpdoc/v6r1/index.jsp?topic=/com.ibm.wp.ent.doc_v615/admin/srvcfgref.html

Mitigation(s):
Apply the workaround until the APAR is installed.


CHANGE HISTORY
28 May 2013: Original Copy Published


*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.


Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.


Related information

Complete CVSS Guide
On-line Calculator V2
CVE-2013-2950
X-Force Vulnerability Database
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog


Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

WebSphere Portal

Software version:

6.1, 7.0, 8.0

Operating system(s):

AIX, HP-UX, IBM i, Linux, Solaris, Windows, i5/OS, z/OS

Reference #:

1638864

Modified date:

2013-05-28

Translate my page

Machine Translation

Content navigation