IBM Support

Security Bulletin: Security vulnerabilities in IBM Java Runtime and Apache Tomcat affects IBM RLKS Administration and Reporting Tool Admin (CVE-2016-5597, CVE-2016-3092)

Security Bulletin


Summary

There is a vulnerability related to the Networking component in IBM® Runtime Environment Java™ Technology Edition, Version 6.0.16.0, that is used and shipped by IBM Rational License Key Server Administration and Reporting Tool Admin.

Vulnerability Details

CVEID: CVE-2016-5597
DESCRIPTION:
An unspecified vulnerability in Oracle Java SE and Java SE Embedded related to the Networking component could allow a remote attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/118071 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID: CVE-2016-3092
DESCRIPTION:
Apache Tomcat is vulnerable to a denial of service, caused by an error in the Apache Commons FileUpload component. By sending file upload requests, an attacker could exploit this vulnerability to cause the server to become unresponsive.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114336 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

These vulnerabilities impact following components and their releases:

  • RLKS Administration and Reporting Tool version 8.1.4
  • RLKS Administration and Reporting Tool version 8.1.4.2
  • RLKS Administration and Reporting Tool version 8.1.4.3
  • RLKS Administration and Reporting Tool version 8.1.4.4
  • RLKS Administration and Reporting Tool version 8.1.4.5
  • RLKS Administration and Reporting Tool version 8.1.4.6
  • RLKS Administration and Reporting Tool version 8.1.4.7
  • RLKS Administration and Reporting Tool version 8.1.4.8
  • RLKS Administration and Reporting Tool version 8.1.4.9

Remediation/Fixes

For CVE-2016-5597

Replace the JRE used in IBM RLKS Administration and Reporting Tool and IBM RLKS Administration Agent.

Steps to replace the JRE in IBM RLKS Administration and Reporting Tool (All Versions)



1. Go to Fix Central

2. On the Find product tab, enter Rational Common Licensing in the Product Selector field and hit enter.

3. Select the Installed Version and hit continue button.

4. Select the platform of the machine where RLKS Administration and Reporting Tool is installed and hit continue button.

5. On the Identify fixes page, select Browse for fixes and select Show fixes that apply to this version and hit continue button.

6. Download the Java 6 runtime iFix for RLKS Administration and Reporting Tool that is applicable for your target platform.

Note:
Although the name of the iFix is RLKS_Administration_And_Reporting_Tool_8149_iFix_9, the same ifix is applicable to all previous RLKS Administration and Reporting Tool versions.

7. Shutdown RLKS Administration and Reporting Tool.

8. Go to the installation location of RLKS Administration and Reporting Tool.

9. Rename <install location>/server/jre folder to <install location>/server/jre_back. This step backs up the existing JRE.

10. Extract the downloaded JRE into <install location>/server folder.

Example: <install location>/server/jre

11. Startup RLKS Administration and Reporting Tool.

12. Login to the tool using rcladmin user and verify that you see the configured license servers under 'Server' tab.


For CVE-2016-3092

Follow the instructions below.

1. Go to Fix Central

2. On the Find product tab, enter Rational Common Licensing in the Product Selector field and hit enter.

3. Select the Installed Version and hit continue button.

4. Select the platform of the machine where RLKS Administration and Reporting Tool is installed and hit continue button.

5. On the Identify fixes page, select Browse for fixes and select Show fixes that apply to this version and hit continue button.

6. Download the file named Apache_Commons_File_Upload_Library_1.3.2.zip.

Note:
Although the name of the iFix is RLKS_Administration_And_Reporting_Tool_8149_iFix_9, the same ifix is applicable to all previous RLKS Administration and Reporting Tool versions.

7. Shutdown RLKS Administration and Reporting Tool.

8. Uncompress the file.

9. Launch IM and point it to use this iFix via the file <ifix09/repository.config>.

10. Complete the Update of the RLKS Administration and Reporting Tool through IM.

11. Restart RLKS Administration and Reporting Tool.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

22 December 2016 : Original version published
04 January 2017: Misspelling in the Remediation/Fixes corrected

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSTMW6","label":"Rational License Key Server"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"RLKS Administration and Reporting Tool","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.1.4;8.1.4.2;8.1.4.3;8.1.4.4;8.1.4.5;8.1.4.6;8.1.4.7;8.1.4.8;8.1.4.9","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Product Synonym

IBM RLKS Administration and Reporting Tool

Document Information

Modified date:
17 June 2018

UID

swg21995448