Lucene search

K
ibmIBM35E556B30CB2660B16E794EA5F18B8557A4A13AAB782A9BB0AF2A0BA7366134F
HistorySep 10, 2020 - 3:43 p.m.

Security Bulletin: A Security Vulnerability exists in the Dojo runtime that affects Rational Software Architect and Rational Software Architect for Websphere Software

2020-09-1015:43:59
www.ibm.com
9

EPSS

0.004

Percentile

73.4%

Summary

The dojox/form/resources/fileuploader.swf, dojox/form/resources/uploader.swf, dojox/av/resources/audio.swf, and dojox/av/resources/video.swf files exhibit an cross-site scripting (XSS) vulnerability. Any web application using the IBM Dojo Toolkit and providing those files might be subject to this vulnerability.

Vulnerability Details

CVEID: CVE-2014-8917**
DESCRIPTION:** IBM Dojo Toolkit is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victimโ€™s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victimโ€™s cookie-based authentication credentials.

CVSS Base Score: 4.3
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/99303&gt;_ for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

Dojo 1.4 and 1.5 packaged with Rational Software Architect and Rational Software Architect for WebSphere Software 8.0.x and 8.5.x

Remediation/Fixes

Update the Dojo runtime provided by the product to address this vulnerability:

For Dojo version 1.4 included with IBM Rational Software Architect and Rational Software Architect for WebSphere Software Version 8.0.x or Version 8.5.x
1. On the Select Fixes page, select interim fix: Rational-dojo141-CVE-2014-8917-ifix (Fix for the CVE-2014-8917 vulnerability in Dojo)

For Dojo version 1.5 included with IBM Rational Software Architect and Rational Software Architect for WebSphere Software Version 8.5.x
1. On the Select Fixes page, select interim fix: Rational-dojo15-CVE-2014-8917-ifix (Fix for the CVE-2014-8917 vulnerability in Dojo)

Product VRMF Remediation/Fix
Rational Software Architect

Rational Software Architect for WebSphere Software| 8.0 to 8.0.4.2Ifix1

8.5 to 8.5.5.3| Rational-dojo141-CVE-2014-8917-ifix

Rational-dojo15-CVE-2014-8917-ifix

Instructions to download and install the update from the compressed files
1. Locate your existing Dojo installation folder in your projects; for example; Project/WebContent/dojo. To find your specific location, follow these instructions:

1.Right-click on your Web project and select Properties
2.Click on the Dojo Toolkit page
3.Look at the path specified in the Dojo Project Setup Summary section 2. Backup your existing Dojo installation by renaming the folder to; for example; Project/WebContent/dojo.bak/
3. Recreate the original Dojo installation folder; for example, Project/WebContent/dojo/
4. Download the updated Dojo runtime from the link listed in the Remediation**/Fix** in above table and save it to the Dojo installation folder from step 3
5. Extract the compressed Dojo archive into your Dojo installation folder

Workarounds and Mitigations

None

EPSS

0.004

Percentile

73.4%

Related for 35E556B30CB2660B16E794EA5F18B8557A4A13AAB782A9BB0AF2A0BA7366134F