Lucene search

K
ibmIBM21E57C35FE09E38530763BFCDAD66100DAF8064F097BD72BEE9D9815E72B3FF7
HistoryJun 16, 2018 - 9:49 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by a potential information exposure vulnerability (CVE-2016-5919)

2018-06-1621:49:22
www.ibm.com
11

EPSS

0.002

Percentile

53.2%

Summary

IBM Security Access Manager appliances use weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information.

Vulnerability Details

CVEID: CVE-2016-5919**
DESCRIPTION:** IBM Security Access Manager for Web uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVSS Base Score: 5.9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/115599&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 7.0 (appliance) IV90724 Apply Interim Fix 28:
7.0.0-ISS-WGA-IF0028
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.4 IV90691 Upgrade to 8.0.1.5:
8.0.1-ISS-WGA-FP0005
IBM Security Access Manager for Mobile 8.0.0.0 -
8.0.1.4 IV90709 Upgrade to 8.0.1.5:
8.0.1-ISS-ISAM-FP0005
IBM Security Access Manager 9.0 -
9.0.2.0 IV90509 Upgrade to 9.0.2.1:
9.0.2-ISS-ISAM-FP0001

Workarounds and Mitigations

None.

EPSS

0.002

Percentile

53.2%

Related for 21E57C35FE09E38530763BFCDAD66100DAF8064F097BD72BEE9D9815E72B3FF7