IBM Support

Rational DOORS Web Access is affected by Apache Tomcat vulnerabilities (CVE-2015-5345, CVE-2015-5351)

Security Bulletin


Summary

The Apache Tomcat application server in installations of IBM Rational DOORS Web Access version contains security vulnerabilities.

Vulnerability Details

Some versions of Rational DOORS Web Access are shipped with an Apache Tomcat application server that contains security vulnerabilities. Apache Tomcat has been updated to incorporate fixes for these vulnerabilities.

Rational DOORS Web Access is affected by the following vulnerabilities:
CVEID: CVE-2015-5345
Description:
 Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by an error when accessing a protected directory. By redirecting to the URL, an attacker could exploit this vulnerability to determine the presence of a directory.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110857 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2015-5351
Description:
 Apache Tomcat is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input by the index page. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform unauthorized actions. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
CVSS Base Score: 8.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110859 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Affected Products and Versions

Rational DOORS Web Access version 9.6.1.4, 9.6.1.3, 9.6.1.2, 9.6.1.1, 9.6.1.0, 9.6.0.x, 9.5.2.x, 9.5.1.x, 9.5.0.x, 1.5.0.x, 1.4.0.x.

Remediation/Fixes

Upgrade to one of the versions of Apache Tomcat shown in the table below. You can upgrade Apache Tomcat after installing Rational DOORS Web Access.

To obtain the updated version of the Apache Tomcat, contact IBM Support.


Support can help identify the latest Apache Tomcat that is compatible with your operating system and platform. Publicly available versions of the Apache Tomcat are not supported with Rational DOORS Web Access.

The following table presents Rational DOORS Web Access versions and the released versions of Apache Tomcat.

Rational DOORS Web Access Apache Tomcat
1.4.0.4 6.0.45
1.5.0.x 6.0.45
9.5.0.x 6.0.45
9.5.1.x 6.0.45
9.5.2.x 6.0.45
9.6.0.x 7.0.68
9.6.1.x 7.0.68

After you obtain the Apache Tomcat update from Support do these steps:

Procedure:

  1. Go to the Rational DOORS Web Access installation directory.

    For example:
    C:\Program Files\IBM\Rational\DOORS Web Access\9.version

  2. Rename the server directory to server.orig.

  3. Extract the Apache Tomcat server archive that was supplied by Support to ./server in the Rational DOORS Web Access installation directory.

  4. Copy your ./server.orig/festival directory to ./server/festival.

  5. Copy the ./server.orig/conf/server.xml file to ./server/conf/server.xml.

  6. Copy ./server.orig/webapps/*.war to ./server/webapps.

  7. Optional: Copy any customized files from the ./server.orig directory to ./server.

  8. UNIX systems only: Run the ./configure-festival.sh command, as described in the help topic Installing the web access server and the web access broker on Linux or Solaris systems.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Related information

Acknowledgement

None

Change History

*16 March 2016: Original copy published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: Rational DOORS Web Access
General Information

Software version: 1.4, 1.4.0.1, 1.4.0.2, 1.4.0.3, 1.4.0.4, 1.4.0.5, 1.5, 1.5.0.1, 9.5, 9.5.0.1, 9.5.1, 9.5.1.1, 9.5.2, 9.5.2.1, 9.6, 9.6.0.1, 9.6.1, 9.6.1.1, 9.6.1.3, 9.6.1.4

Operating system(s): Windows

Reference #: 1978300

Modified date: 16 March 2016