IBM Support

Security Bulletin: Rational License Key Server Administration and Reporting Tool vulnerability (CVE-2014-0411)

Security Bulletin


Summary

A possible security vulnerability has been reported in the Rational License Key Server Administration and Reporting Tool. There have been no reported exploits of this possible vulnerability, which is located in the JSSE component of IBM Java shipped with the tool and its agent.

Vulnerability Details

Subscribe to My Notifications to be notified of important product support alerts like this.
  • Follow this link for more information (requires login with your IBM ID)

CVE ID: CVE-2014-0411

Description: An unspecified vulnerability related to the JSSE component has partial impact to confidentiality and integrity. The exploit is not trivial and it requires a man-in-the-middle position and a long session time of around 20 hours. The likelihood of occurrence of this issue in RLKS Administration and Reporting tool and RLKS Administration Agent is low since the application has a session timeout of 30 minutes.

CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/90357 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/H:Au/N:C/P:I/P:A/N)

Affected Products and Versions

This vulnerability impacts the following RLKS components and its releases:

  • IBM Rational License Key Server (RLKS) Administration and Reporting Tool version 8.1.4
  • IBM Rational License Key Server (RLKS) Administration and Reporting Tool version 8.1.4.2
  • IBM Rational License Key Server (RLKS) Administration Agent version 8.1.4
Note: This vulnerability has been fixed in RLKS Administration Agent version 8.1.4.2.

Remediation/Fixes

Replace the JRE used in RLKS:

Steps to replace the JRE in RLKS Administration and Reporting Tool version 8.1.4 and 8.1.4.2
Steps to replace the JRE in RLKS Administration Agent version 8.1.4



Steps to replace the JRE in RLKS Administration and Reporting Tool version 8.1.4 and 8.1.4.2:
  1. Go to Fix Central

  2. On the Find product tab, enter Rational Common Licensing in the Product Selector field and hit enter.

  3. Select 8.1.4 or 8.1.4.2 as the Installed Version and hit continue button.

  4. Select the platform of the machine where RLKS Administration and Reporting Tool is installed and hit continue button.

  5. On the Identify fixes page, select Browse for fixes and select Show fixes that apply to this version and hit continue button.

  6. Download the Java runtime ifix (iFix 2) for RLKS Administration and Reporting Tool.

    Note: Although the name of the ifix is RLKS_Administration_And_Reporting_Tool_8142_Admin_iFix_2, the same ifix is applicable to RLKS Administration and Reporting Tool version 8.1.4 as well as 8.1.4.2.

  7. Shutdown RLKS Administration and Reporting Tool.

  8. Go to the installation location of RLKS Administration and Reporting Tool.

  9. Rename <install location>/server/jre folder to <install location>/server/jre_back.
    This step backs up the existing JRE.

  10. Extract the downloaded JRE into <install location>/server/ folder
    Example: <install location>/server/jre

  11. Startup RLKS Administration and Reporting Tool.

  12. Login to the tool using rcladmin user and verify that you see the configured license servers under 'Server' tab.



Steps to replace the JRE in RLKS Administration Agent version 8.1.4:

Note: This vulnerability has been fixed in RLKS Administration Agent 8.1.4.2. If you cannot upgrade the agent, follow the below steps to fix the vulnerability.
  1. Go to Fix Central

  2. On the Find product tab, enter Rational Common Licensing in the Product Selector field and hit enter.

  3. Select 8.1.4 as the Installed Version and hit continue button.

  4. Select the platform of the machine where RLKS Administration and Reporting Tool is installed and hit continue button.

  5. On the Identify fixes page, select Browse for fixes and select Show fixes that apply to this version and hit continue button.

  6. Download the Java runtime ifix for RLKS Administration Agent. Name of this ifix is like RLKS_Administration_And_Reporting_Tool_814_Agent_iFix_4.

  7. Shutdown RLKS Administration Agent.

  8. Go to the installation location of RLKS Administration Agent.

  9. Rename <install location>/jre folder to <install location>/jre_back.
    This step backs up the existing JRE.

  10. Extract the downloaded JRE into <install location>/ folder
    Example: <install location>/jre

  11. Startup RLKS Administration Agent

  12. Go to RLKS Administration and Reporting Tool.
    • Verify that you see the configured license servers under Server tab.
    • Select the license server for which the JRE for agent was replaced with the above steps.

  13. If you are using reporting functionality:
    • Go to Reporting tab.
    • Go to Action button and click Start Reporting operation.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSTMW6","label":"Rational License Key Server"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"RLKS Administration and Reporting Tool","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.1.4;8.1.4.2","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 June 2018

UID

swg21666157