Lucene search

K
ibmIBM53BCE57A04E1D3F43A06B36B0C3FF3517470A5AE85FA597D3849BDF86222D82B
HistoryJun 17, 2018 - 3:51 p.m.

Security Bulletin: Information disclosure in WebSphere Application Server shipped with Tivoli Integrated Portal (CVE-2017-1681)

2018-06-1715:51:21
www.ibm.com
9

0.0004 Low

EPSS

Percentile

5.1%

Summary

There is a potential information disclosure vulnerability in WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2017-1681**
DESCRIPTION:** IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/134003 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Tivoli Integrated Portal version 2.1.0 - 2.1.0.5

Tivoli Integrated Portal version 2.2.0.0 - 2.2.0.19

Remediation/Fixes

Principal Product and Version(s)

| Affected Supporting Product and Version| Affected Supporting Product Security Bulletin
—|—|—
Tivoli Integrated Portal version

2.1.0 - 2.1.0.5

2.2.0 - 2.2.0.19

| embedded Websphere Application Server version 7.0.x| Security Bulletin: Information disclosure in WebSphere Application Server (CVE-2017-1681)

The Websphere security bulletin above provides a link to the required iFix to remediate the vulnerability. However, the iFix requires either eWAS 7.0.0.31 or higher installed.

TIP does not support upgrading Websphere fixpack independently. TIP 2.2.0.15 or TIP 2.2.0.17 or TIP 2.2.0.19 must be applied which will upgrade eWAS to 7.0.0.31 and above. Once TIP FP has been applied, the Websphere iFix can be applied as described in the Websphere bulletin.

Workarounds and Mitigations

Please refer to WAS iFix as described above

0.0004 Low

EPSS

Percentile

5.1%

Related for 53BCE57A04E1D3F43A06B36B0C3FF3517470A5AE85FA597D3849BDF86222D82B