Security Bulletin: IBM Operational Decision Manager and WebSphere ILOG JRules: Multiple security vulnerabilities in IBM JRE

Security Bulletin


Summary

This Security Bulletin addresses the security vulnerabilities that have shipped with the IBM Java Runtime Environment (JRE) included in IBM Operational Decision Manager and IBM ILOG JRules. IBM ODM and ILOG JRules now include the most recent version of the IBM JRE which fixes the security vulnerabilities reported in Oracle's Critical Patch Update releases of October 2013.

Vulnerability Details

CVE ID

CVE-2013-5850,CVE-2013-5838,CVE-2013-5802,CVE-2013-3829,CVE-2013-5820,CVE-2013-4002,CVE-2013-5825,CVE-2013-5840,CVE-2013-5851,CVE-2013-5790,CVE-2013-5780,CVE-2013-5458,CVE-2013-5456,CVE-2013-5457,CVE-2013-5375,CVE-2013-5372

DESCRIPTION


There are a number of vulnerabilities in the IBM SDK, Java Technology Edition that affect various components. CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a security manager to escalate its privileges by modifying or removing the security manager. These vulnerabilities could occur when untrusted code is executed under a security manager, or when the IBM SDK, Java Technology Edition has been associated with a web browser for running applets and Web Start applications.

CVE-2013-5372 is a denial of service vulnerability which could result in a complete availability impact on the affected system.

This bulletin also covers all applicable CVEs published by Oracle as part of their October 2013 Java SE Critical Patch Update. For more information please refer to Oracle's October 2013 Java SE CPU Advisory.

CVEID: CVE-2013-5456
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88255 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2013-5457
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88256 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2013-5458
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88257 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2013-5838
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87974 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2013-5850
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87973 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVEID: CVE-2013-5802
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87982 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/P:A/P)

CVEID: CVE-2013-4002
CVSS Base Score: 7.1
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/85260 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVEID: CVE-2013-3829
CVSS Base Score: 6.4
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87986 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C)

CVEID: CVE-2013-5820
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87996 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC/L:Au:N/C:N/I:P/A:N)

CVEID: CVE-2013-5825
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87988 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC/L:Au:N/C:N/I:N/A:P)

CVEID: CVE-2013-5840
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87998 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC/L:Au:N/C:P/I:N/A:N)

CVEID: CVE-2013-5851
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87997 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC/L:Au:N/C:P/I:N/A:N)

CVEID: CVE-2013-5372
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/86662 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVEID: CVE-2013-5375
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/86901 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVEID: CVE-2013-5780
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88001 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C/P:I:N/A:N)

CVEID: CVE-2013-5790
CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/88004 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products

IBM WebSphere ILOG JRules v7.1,

IBM WebSphere Operational Decision Management v7.5

IBM Operational Decision Manager v8.0

IBM Operational Decision Manager v8.5

Remediation/Fixes

For IBM WebSphere ILOG JRules V7.1 an interim fix for APAR RS01493 is available from IBM Fix Central: 7.1.1.5-WS-BRMS_JDK-WIN-IF032.


For IBM Operational Decision Manager interim fixes for APAR RS01493 are available on Fix Central:

  • v7.5 Interim Fix 35: 7.5.0.4-WS-ODM_JDK-<OS>-IF035
  • v8.0 Interim Fix 22: 8.0.1.1-WS-ODM_JDK-<OS>-IF022
  • v8.5 Interim Fix 17: 8.5.0.0-WS-ODM_JDK-<OS>-IF017
If you are using WebSphere ILOG JRules V7.0 we recommend upgrading to the latest version before End of Service in 2014. In case you need this update you can install the interim fix provided for JRules V7.1 to refresh the IBM JRE.

Workarounds/Mitigations

None known, apply fixes

References:

Complete CVSS Guide
On-line Calculator V2

Change History

None

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Rate this page:

(0 users)Average rating

Document information


More support for:

IBM Operational Decision Manager
Maintenance

Software version:

7.1, 7.5, 8.0, 8.5

Operating system(s):

Platform Independent

Reference #:

1661213

Modified date:

2014-01-07

Translate my page

Machine Translation

Content navigation