Lucene search

K
ibmIBM1D9B7C40E361F94A2AD8CF5D6A4095E97C0FD0850D34A0405B7D7E2A2B5ECE5E
HistoryJun 16, 2018 - 9:48 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by an XML External Entity Injection vulnerability (CVE-2016-3027)

2018-06-1621:48:06
www.ibm.com
9

EPSS

0.001

Percentile

49.7%

Summary

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.

Vulnerability Details

CVEID: CVE-2016-3027**
DESCRIPTION:** IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114475 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H)

Affected Products and Versions

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.4 IV90686 Upgrade to 8.0.1.5:
8.0.1-ISS-WGA-FP0005
IBM Security Access Manager for Mobile 8.0.0.0 -
8.0.1.4 IV90704 Upgrade to 8.0.1.5:
8.0.1-ISS-ISAM-FP0005
IBM Security Access Manager 9.0 - 9.0.1.0 IV90504 Upgrade to 9.0.2.0:
IBM Security Access Manager V9.0.2 Multiplatform, Multilingual (CRW4EML)

Workarounds and Mitigations

None.

EPSS

0.001

Percentile

49.7%

Related for 1D9B7C40E361F94A2AD8CF5D6A4095E97C0FD0850D34A0405B7D7E2A2B5ECE5E