IBM Support

Security Bulletin: Multiple potential vulnerabilites in IBM OpenPages GRC Platform

Security Bulletin


Summary

The following security vulnerabilities have been identified in versions of IBM OpenPagesGRC Platform. See Vulnerability Details section for more information.

Vulnerability Details

Customers who have IBM OpenPages GRC platform are potentially impacted by the following vulnerabilities:


CVEID: CVE-2015-0143
DESCRIPTION:
IBM OpenPages GRC Platform could allow an authenticated attacker to obtain sensitive information from error messages.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100754 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVEID: CVE-2015-0142
DESCRIPTION:
IBM OpenPages GRC Platform could allow an authenticated user to turn the server into maintenance mode due to nsufficient access checking for System Administration Mode function which would disallow users to save data.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100753 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVEID: CVE-2015-0141
DESCRIPTION:
IBM OpenPages GRC Platform contains insufficient access control on JSON requests which could allow an authenticated user to alter user filters.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100752 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVEID: CVE-2015-0144
DESCRIPTION:
IBM OpenPages GRC Platform is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100759 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVEID: CVE-2015-0145
DESCRIPTION:
IBM OpenPages GRC Platform is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100760 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVEID: CVE-2014-8916
DESCRIPTION:
IBM OpenPages GRC Platform is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99302 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Affected Products and Versions

IBM OpenPages with Application Server 6.2 through 7.1

Remediation/Fixes

Fixes have been created to remediate all affected versions of the named product. Download and install the fix as soon as practical. The fix and installation instructions are available at the URL listed below


Running Version Patch Version Download URL
IBM OpenPages GRC Platform 7.1 7.1 FP1 http://www.ibm.com/support/docview.wss?uid=swg24040169
IBM OpenPages GRC Platform 7.0 7.0 FP4 http://www.ibm.com/support/docview.wss?uid=swg24039998
IBM OpenPages GRC Platform 6.2.1 6.2.1.1 IF5 http://www.ibm.com/support/docview.wss?uid=swg24040558
IBM OpenPages GRC Platform 6.2 6.2 IF7 http://www.ibm.com/support/docview.wss?uid=swg24040557

Workarounds and Mitigations

No known workaround. Please apply appropriate fix release.

Get Notified about Future Security Bulletins

References

Complete CVSS v2 Guide
On-line Calculator v2

Related information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: OpenPages GRC Platform

Software version: 6.2, 6.2.1, 7.0, 7.1

Operating system(s): Platform Independent

Reference #: 1963358

Modified date: 24 February 2017


Translate this page: