Security Bulletin: Multiple vulnerabilities in IBM Infosphere Optim Data Growth for Oracle E-Business Suite (CVE-2013-0577, CVE-2013-0579, CVE-2013-0580)

Flash (Alert)


Abstract

Multiple vulnerabilities exist in the Optim E-Business Console that can allow an attacker to view sensitive information, perform actions as an impersonated legitimate user, or upload, modify or delete web pages or scripts on the server.

Content

VULNERABILITY DETAILS:

CVE ID: CVE-2013-0577

DESCRIPTION: A malicious user who has successfully authenticated can upload, modify or delete web pages or scripts in the Optim E-Business Console. An exploit will not impact accessibility of system resources or the confidentiality of information, but the integrity of the system could be compromised.

CVSS:
CVSS Base Score: 2.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83329 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:N/I:P/A:N)

CVE ID: CVE-2013-0579

DESCRIPTION: An attacker with access to a user’s open browser before the user authenticates with the Optim E-Business Console or a browser left open after the user has authenticated, regardless of how long, can gather information to allow the attacker to impersonate that user including viewing sensitive information and performing any actions as available to the impersonated user in any environment that can access to the Optim E-Business Console. An exploit will not impact accessibility of system resources but both the confidentiality of information and the integrity of the system and data could be compromised.

CVSS:
CVSS Base Score: 3.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83331 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:P/I:P/A:N)

CVE ID: CVE-2013-0580

DESCRIPTION: The Optim E-Business Console is vulnerable to cross-site request forgery which can allow an attacker to trick a legitimate user into opening a URL that results in an action being taken as that user, potentially without the knowledge of that user. Any actions taken require the user being tricked to either be previously authenticated or to authenticate as part of the attack. An exploit will not impact accessibility of system resources but both the confidentiality of information and the integrity of the system and data could be compromised.

CVSS:
CVSS Base Score: 2.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/83332 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:N/I:P/A:N)

AFFECTED PRODUCTS:
Versions 6.0 through 9.1 of IBM Infosphere Optim Data Growth for Oracle E-Business Suite are affected.

REMEDIATION: The recommended solution is to apply the fix as soon as possible.

Fix:
Apply iFix OEBS-07.01.02_09.01.00-017, located here:

http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~Information+Management&product=ibm/Information+Management/Optim&release=OracleApps.9.1.0&platform=All&function=all

Workaround(s) & Mitigations:
None known, apply fixes

REFERENCES:

· Complete CVSS Guide
· On-line Calculator V2

RELATED INFORMATION:
· IBM Secure Engineering Web Portal
· IBM Product Security Incident Response Blog

CHANGE HISTORY:
4-Oct-2013: Original version published
10-Oct-2013: Updated

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.


Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.


Rate this page:

(0 users)Average rating

Add comments

Document information


More support for:

Optim
Data Growth Solution for Oracle E-business Suite

Software version:

6.0, 6.0.2, 6.1, 7.1.0, 7.1.1, 7.1.2, 8.1, 9.1

Operating system(s):

AIX, HP Itanium, HP-UX, Linux, Linux on System z, Solaris, Windows, i5/OS, z/OS

Reference #:

1651990

Modified date:

2013-10-10

Translate my page

Machine Translation

Content navigation