IBM Support

Security Bulletin: Code execution vulnerability in WebSphere Application Server (CVE-2018-1567)

Security Bulletin


Summary

There is a potential remote code execution vulnerability in WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2018-1567
DESCRIPTION: IBM WebSphere Application Server could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/143024 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

This vulnerability affects the following versions and releases of IBM WebSphere Application Server:

  • Version 9.0
  • Version 8.5
  • Version 8.0
  • Version 7.0

Remediation/Fixes

 This set of fixes for PH03986 are replacements for those originally provided for APAR PI95973.  If you have PI95973 installed, you must install this new interim fix.  PH03986 includes the vulnerability fix from PI95973 and an additional fix for a problem it causes in some environments.   There is no need to uninstall the fix for PI95973 before installing the fix for PH03986.

With this iFix applied, during server shutdown, you may see an FFDC for an java.lang.reflect.UndeclaredThrowableException error in the application server log.  This FFDC is not an artifact of the original security vulnerability and can be ignored at this time.

The recommended solution is to apply the interim fix, Fix Pack or PTF containing APAR PH03986 for each named product as soon as practical.

For WebSphere Application Server traditional and WebSphere Application Server Hypervisor Edition:


For V9.0.0.0 through 9.0.0.9:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH03986
--OR--
· Apply Fix Pack 9.0.0.10 or later (targeted availability 4Q2018)

For V8.5.0.0 through 8.5.5.14:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH03986
--OR--
· Apply Fix Pack 8.5.5.15 or later  (targeted availability 1Q2019)

For V8.0.0.0 through 8.0.0.15:
· Upgrade to fix pack level 8.0.0.15 and then apply Interim Fix PH03986

For V7.0.0.0 through 7.0.0.45:
· Upgrade to fix pack level 7.0.0.45 and then apply Interim Fix PH03986


WebSphere Application Server V7 and V8 are no longer in full support; IBM recommends upgrading to a fixed, supported version/release/platform of the product.


 

Get Notified about Future Security Bulletins

Important Note

IBM strongly suggests that all System z customers be subscribed to the System z Security Portal to receive the latest critical System z security and integrity service. If you are not subscribed, see the instructions on the System z Security web site. Security and integrity APARs and associated fixes will be posted to this portal. IBM suggests reviewing the CVSS scores and applying all security or integrity fixes as soon as possible to minimize any potential risk.

Reference

Complete CVSS v3 Guide
On-line Calculator v3

Related Information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Change History

05 September 2018: original document published
10 October 2018: fix pulled due to regression
13 October 2018: publish corrected fix
13 October 2018: minor wording update under remediation/fixes

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: WebSphere Application Server

Component: --, ">More...

Software version: 7.0, 8.0, 8.5, 9.0

Operating system(s): AIX, HP-UX, IBM i, Linux, Solaris, Windows, z/OS

Software edition: Advanced, Base, Developer, Enterprise, Express, Network Deployment, Single Server

Reference #: 2016254

Modified date: 13 October 2018


Translate this page: