IBM Support

Security Bulletin: Multiple Vulnerabilities in IBM iNotes (CVE-2013-0589, CVE-2013-0592, CVE-2013-0594, CVE-2013-0595)

Security Bulletin


Summary

IBM iNotes versions prior to 8.5.3 Fix Pack 6 and 9.0.1 contain multiple security vulnerabilities: CVE-2013-0589, CVE-2013-0592, CVE-2013-0594 and CVE-2013-0595.

Vulnerability Details

CVE ID: CVE-2013-0589
DESCRIPTION: IBM iNotes contains a privacy vulnerability. By sending an email message containing specially crafted markup, a remote unauthenticated attacker could circumvent the remote image filtering feature, giving the attacker an opportunity to confirm a user has read a message or provide the basis for further attacks.

CVSS:
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83371 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0592
DESCRIPTION: IBM iNotes contains a reflected cross-site scripting vulnerability. By tricking a user into following a specially crafted link, a remote unauthenticated attacker could exploit this security vulnerability to execute commands as the logged-in user and/or expose user personal data.

CVSS:
CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83815 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: Single Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0594
DESCRIPTION: IBM iNotes contains an open redirect vulnerability, allowing attackers to produce URLs which look trusted but may redirect to arbitrary URLs. By tricking a user into following one of these links, a remote unauthenticated attacker could exploit this security vulnerability to execute commands as the logged-in user and/or expose user personal data.

CVSS:
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83383 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: None Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None


CVE ID: CVE-2013-0595
DESCRIPTION: IBM iNotes contains two cross-site scripting vulnerabilities (assigned the same CVE ID). By sending an email message containing specially crafted markup, a remote unauthenticated attacker could exploit this security vulnerability to execute commands as the logged-in user and/or expose user personal data.

CVSS:
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83431 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Access Vector: Network Access Complexity: Medium
Authentication: None Confidentiality Impact: None
Integrity Impact: Partial Availability Impact: None

Affected Products and Versions

IBM iNotes version 9.0.

IBM iNotes versions 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2 and 8.5.3 prior to 8.5.3 Fix Pack 6.

Remediation/Fixes

These issues are being tracked as SPR# PTHN95QMLK (CVE-2013-0589), SPR# PTHN95PNV2 (CVE-2013-0592 and CVE-2013-0594), SPR# PTHN95TKZ9 (CVE-2013-0594), and SPR #s PTHN95TKZ9 and PTHN95WMFP (CVE-2013-0595).

The fixes were introduced starting in IBM Domino and iNotes versions 9.0.1 and 8.5.3 Fix Pack 6. See the technotes linked below for the latest available Fix Packs and Interim Fixes.


To close the vulnerabilities completely, all fixes must be applied. To inquire about the possibility of obtaining an Interim Fix (hotfix) for earlier releases, open a service request with IBM Support.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

Important note

IBM strongly suggests that all System z customers be subscribed to the System z Security Portal to receive the latest critical System z security and integrity service. If you are not subscribed, see the instructions on the System z Security web site. Security and integrity APARs and associated fixes will be posted to this portal. IBM suggests reviewing the CVSS scores and applying all security or integrity fixes as soon as possible to minimize any potential risk.

References

Complete CVSS v2 Guide
On-line Calculator v2

Acknowledgement
This vulnerability was reported to IBM by Alexander Klink, n.runs AG.

Related information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Cross reference information
Segment Product Component Platform Version Edition
Messaging Applications IBM Domino

Document information

More support for: IBM iNotes
Security

Software version: 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, 9.0

Operating system(s): AIX, Android, IBM i, Linux, OS X, Solaris, Windows, iOS

Reference #: 1671622

Modified date: 02 May 2014


Translate this page: