Security Bulletin
Summary
Monitoring Agent for WebSphere Applications (WebSphere Applications agent for short), which is delivered in the Cloud APM product, has addressed the following vulnerability:
-- The privacy filter used by the WebSphere Applications agent does not shield PCI data when the diagnostics or transaction tracking is enabled for the agent.
Vulnerability Details
CVEID: CVE-2018-1387
DESCRIPTION: Monitoring Agent for WebSphere Applications may reveal sensitive personal information to the staff who have access to the database of the Cloud APM product.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/138210 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Affected Products and Versions
- IBM Cloud Application Performance Management, Base Private 8.1.4
- IBM Cloud Application Performance Management, Advanced Private 8.1.4
- IBM Cloud Application Performance Management 8.1.4
- IBM Performance Management 8.1.3
- Cloud APM Data Collector 7.3
- Cloud APM Data Collector 7.4
Remediation/Fixes
Product | Product Version | APAR | Remediation / First Fix |
IBM Cloud APM - Monitoring agent for WebSphere Applications | v8.1.4 | The vulnerabilities can be remediated by applying the 8.1.4.0-IBM-APM-WAS-AGENT-IF0004 patch to all systems where this agent is installed: https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003687 | |
IBM Performance Managemennt - Monitoring agent for WebSphere Applications | v8.1.3 | The vulnerabilities can be remediated by applying the 8.1.3.0-IBM-IPM-WAS-AGENT-IF0011 patch to all systems where this agent is installed: https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003606 | |
IBM Cloud APM - Liberty data collector for IBM Cloud and on-premises applications | v8.1.4 | The vulnerabilities can be remediated by applying the 8.1.4.0-IBM-APM-LIBERTY-DATACOLLECTOR-IF0002 patch to all systems where this data collector is installed: https://www-01.ibm.com/support/docview.wss?rs=0&uid=isg400003633 | |
IBM Cloud APM Data Collector | v7.4 | The vulnerabilities can be remediated by reinstall data collector with latest build: https://developer.ibm.com/wasdev/downloads/#asset/features-com.ibm.apm.dataCollector-7.4 | |
IBM Cloud APM Data Collector | v7.3 | The vulnerabilities can be remediated by reinstall data collector with latest build: https://developer.ibm.com/wasdev/downloads/#asset/features-com.ibm.apm.dataCollector-7.3 |
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg22014035