Lucene search

K
ibmIBM520FDF8E0502F853691B3866CF26CBC14D341909F74C3D598B36E30C79E71E14
HistoryJun 16, 2018 - 8:03 p.m.

Security Bulletin: IBM Tealeaf Customer Experience Replay Server internal proxy accepts connections from external sources (CVE-2016-5968)

2018-06-1620:03:49
www.ibm.com
7

0.002 Low

EPSS

Percentile

52.0%

Summary

The internal HTTP proxy server deployed as part of the IBM Tealeaf Customer Experience Replay Server accepts requests from any network host, not only from local renderers.

Vulnerability Details

CVEID: CVE-2016-5968**
DESCRIPTION:** IBM Tealeaf Replay Server allows remote attackers to use one of its web services as a proxy to forward HTTP requests to other internal/external Web resources.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/116303 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Tealeaf Customer Experience 8.0-9.0.2

Remediation/Fixes

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM Tealeaf Customer Experience

|

9.0.2A

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.5224_9.0.2A_IBMTealeaf_CXUpgrade_FixPack3_

IBM Tealeaf Customer Experience

|

9.0.2

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.1223_IBMTealeaf_CXUpgrade_FixPack3_

IBM Tealeaf Customer Experience

|

9.0.1A

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.5108_9.0.1A_IBMTealeaf_CXUpgrade_FixPack5_

IBM Tealeaf Customer Experience

|

9.0.1

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.1117_IBMTealeaf_CXUpgrade_FixPack5_

IBM Tealeaf Customer Experience

|

9.0.0, 9.0.0A

| You can contact the Technical Support team for guidance.

IBM Tealeaf Customer Experience

|

8.8

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.8.0.9049_IBMTealeaf_CXUpgrade_FixPack9_

IBM Tealeaf Customer Experience

|

8.7

| _https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.7.1.8847_IBMTealeaf_CXUpgrade_FixPack10_

IBM Tealeaf Customer Experience

|

8.6 and earlier

| You can contact the Technical Support team for guidance.

Workarounds and Mitigations

Limit access to ports 38001 and 38002 on all systems running instances of the Replay Server to local processes.

CPENameOperatorVersion
tealeaf customer experienceeqany

0.002 Low

EPSS

Percentile

52.0%

Related for 520FDF8E0502F853691B3866CF26CBC14D341909F74C3D598B36E30C79E71E14