IBM Support

Security Bulletin: Monitoring Agent for WebSphere Applications is affected by a potential for sensitive personal information to be visible when you use the diagnostics or transaction tracking capability of the agent

Security Bulletin


Summary


Monitoring Agent for WebSphere Applications (WebSphere Applications agent for short), which is delivered in the Cloud APM product, has addressed the following vulnerability:
-- The privacy filter used by the WebSphere Applications agent does not shield PCI data when the diagnostics or transaction tracking is enabled for the agent.

Vulnerability Details

CVEID: CVE-2018-1387
DESCRIPTION: Monitoring Agent for WebSphere Applications may reveal sensitive personal information to the staff who have access to the database of the Cloud APM product.


CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/138210 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

  • IBM Cloud Application Performance Management, Base Private 8.1.4
  • IBM Cloud Application Performance Management, Advanced Private  8.1.4
  • IBM Cloud Application Performance Management 8.1.4
  • IBM Performance Management 8.1.3
  • Cloud APM Data Collector 7.3
  • Cloud APM Data Collector 7.4

Remediation/Fixes

Product

Product Version
APAR
Remediation / First Fix
IBM Cloud APM - Monitoring agent for WebSphere Applicationsv8.1.4

The vulnerabilities can be remediated by applying the 8.1.4.0-IBM-APM-WAS-AGENT-IF0004 patch to all systems where this agent is installed:

https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003687
IBM Performance Managemennt - Monitoring agent for WebSphere Applicationsv8.1.3

The vulnerabilities can be remediated by applying the 8.1.3.0-IBM-IPM-WAS-AGENT-IF0011 patch to all systems where this agent is installed:

https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003606
IBM Cloud APM - Liberty data collector for IBM Cloud and on-premises applicationsv8.1.4

The vulnerabilities can be remediated by applying the 8.1.4.0-IBM-APM-LIBERTY-DATACOLLECTOR-IF0002 patch to all systems where this data collector is installed:

https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003633
IBM Cloud APM Data Collector v7.4

The vulnerabilities can be remediated by reinstall data collector with latest build:


https://developer.ibm.com/wasdev/downloads/#asset/features-com.ibm.apm.dataCollector-7.4
IBM Cloud APM Data Collectorv7.3

The vulnerabilities can be remediated by reinstall data collector with latest build:

https://developer.ibm.com/wasdev/downloads/#asset/features-com.ibm.apm.dataCollector-7.3

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSTFXA","label":"Tivoli Monitoring"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Monitoring Agent for WebSphere Applications - 5725U05WA","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"8.1.3;8.1.4","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg22014035