IBM Support

Security Bulletin: Potential vulnerabilities in IBM OpenPages GRC Platform with Application Server

Security Bulletin


Summary

The following potential security vulnerabilities have been identified in all versions of IBM OpenPages GRC Platform with Application Server. See the Vulnerability Details section for more information.

Vulnerability Details

Customers who have IBM OpenPages GRC Platform with Application Server are potentially impacted by the following vulnerabilities:

CVEID:
CVE-2016-0638
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Java Messaging Service component has partial confidentiality impact, partial integrity impact, and partial availability impact.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112407 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVEID: CVE-2016-0675
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Console component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112410 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVEID: CVE-2016-0688
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Core Components component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112415 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N)

CVEID: CVE-2016-0696
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Console component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 6.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112408 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVEID: CVE-2016-0700
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Console component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112411 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVEID: CVE-2016-3416
DESCRIPTION:
An unspecified vulnerability in Oracle Fusion Middleware related to the WebLogic Server Console component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112412 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

IBM OpenPages GRC Platform with Application Server 7.0.

Remediation/Fixes

The following fix will remediate all vulnerabilities in all affected versions of IBM OpenPages GRC Platform with Application Server. Download and install the fix as soon as practical. The fix and installation instructions are available at the URL listed below:


Patch Download URL
IBM OpenPages GRC Platform with Application Server IF 6http://www.ibm.com/support/docview.wss?uid=swg24042538

Workarounds and Mitigations

None, please apply fix.

Get Notified about Future Security Bulletins

References

Off

Change History

15 July 2016: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSFUEU","label":"IBM OpenPages with Watson"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF033","label":"Windows"}],"Version":"7.0","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
15 June 2018

UID

swg21987642