Security Bulletin: Vulnerability identified in IBM Domino Java Console (CVE-2016-0304)
IBM Domino has a vulnerability in Java Console Authentication (CVE-2016-0304).
DESCRIPTION: IBM Domino could allow a remote attacker to bypass security restrictions, caused by an error in the remote console when a certain unsupported configuration involving UNC share path names is used. An attacker could exploit this vulnerability to bypass the authentication process and possibly execute arbitrary code with SYSTEM privileges. This vulnerability is due to an incomplete fix for CVE-2011-0920.
CVSS Base Score: 8.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111417 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Products and Versions
IBM Domino 9.0.1 FP5 and earlier releases
IBM Domino 9.0 IF4 and earlier releases
IBM Domino 8.5.3 FP6 IF12 and earlier releases
IBM Domino 8.5.2 FP4 IF3 and earlier releases
IBM Domino 8.5.1 FP5 IF3 and earlier releases
IBM Domino 8.5 release
|Product||Version||Fix Download Link|
|IBM Domino||901 FP6||http://www.ibm.com/support/docview.wss?uid=swg24037141|
|IBM Domino||853 FP6 IF13||http://www.ibm.com/support/docview.wss?uid=swg21663874|
IMPORTANT NOTE: The new Java Console delivered in 901 FP6 and 853 FP6 IF13 will interoperate only with Domino servers at the same version (or later). Customers who wish to use the Java Console on earlier server releases will need to maintain the Java console from that release. This is due to the fact that the vulnerability and the consequent fix require that the Java Console and the Domino server be upgraded to a new protocol (TLS 1.2) and new cryptography, both of which have no interoperability with the earlier versions of the Java Console.
Customers who remain on the following releases may open a Service Request with IBM Support and reference SPR KLYHA7MM3J for custom fixes.
- IBM Domino 901 FP5 IFs and earlier (all releases, all FPs, all IFs)
- IBM Domino 853 FP6 IF12 and earlier (all releases, all FPs, all IFs)
Workarounds and Mitigations
As an alternative to the Java Console and Controller, customers may use the Domino Administrator Client for equivalent functionality.
Get Notified about Future Security Bulletins
This vulnerability was reported to IBM by Jonas Vestberg, Sentor
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
More support for:
Software version: 8.5, 8.5.1, 126.96.36.199, 188.8.131.52, 8.5.2, 184.108.40.206, 8.5.3, 220.127.116.11, 9.0, 9.0.1, 18.104.22.168
Operating system(s): AIX, Linux, Windows
Reference #: 1983328
Modified date: 26 May 2016