IBM Support

Security Bulletin: Vulnerability identified in IBM Domino Java Console (CVE-2016-0304)

Security Bulletin


Summary

IBM Domino has a vulnerability in Java Console Authentication (CVE-2016-0304).

Vulnerability Details


CVEID: CVE-2016-0304
DESCRIPTION:
IBM Domino could allow a remote attacker to bypass security restrictions, caused by an error in the remote console when a certain unsupported configuration involving UNC share path names is used. An attacker could exploit this vulnerability to bypass the authentication process and possibly execute arbitrary code with SYSTEM privileges. This vulnerability is due to an incomplete fix for CVE-2011-0920.

Affected Products and Versions

IBM Domino 9.0.1 FP5 and earlier releases
IBM Domino 9.0 IF4 and earlier releases
IBM Domino 8.5.3 FP6 IF12 and earlier releases
IBM Domino 8.5.2 FP4 IF3 and earlier releases
IBM Domino 8.5.1 FP5 IF3 and earlier releases
IBM Domino 8.5 release

Remediation/Fixes

Product Version Fix Download Link
IBM Domino 901 FP6 http://www.ibm.com/support/docview.wss?uid=swg24037141
IBM Domino 853 FP6 IF13 http://www.ibm.com/support/docview.wss?uid=swg21663874

IMPORTANT NOTE: The new Java Console delivered in 901 FP6 and 853 FP6 IF13 will interoperate only with Domino servers at the same version (or later). Customers who wish to use the Java Console on earlier server releases will need to maintain the Java console from that release. This is due to the fact that the vulnerability and the consequent fix require that the Java Console and the Domino server be upgraded to a new protocol (TLS 1.2) and new cryptography, both of which have no interoperability with the earlier versions of the Java Console.

Customers who remain on the following releases may open a Service Request with IBM Support and reference SPR KLYHA7MM3J for custom fixes.

  • IBM Domino 901 FP5 IFs and earlier (all releases, all FPs, all IFs)
  • IBM Domino 853 FP6 IF12 and earlier (all releases, all FPs, all IFs)

Workarounds and Mitigations

As an alternative to the Java Console and Controller, customers may use the Domino Administrator Client for equivalent functionality.

Get Notified about Future Security Bulletins

References

Related information

Acknowledgement

This vulnerability was reported to IBM by Jonas Vestberg, Sentor

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: IBM Domino
Security

Software version: 8.5, 8.5.1, 8.5.1.1, 8.5.1.5, 8.5.2, 8.5.2.4, 8.5.3, 8.5.3.6, 9.0, 9.0.1, 9.0.1.5

Operating system(s): AIX, Linux, Windows

Reference #: 1983328

Modified date: 26 May 2016