Lucene search

K
ibmIBM5711509DD871227FC9F7CD530DA0E06F21DDA1D522E7B1C76AC95D3AD5F6BC07
HistoryAug 03, 2018 - 4:23 a.m.

Security Bulletin: TXSeries for Multiplatforms is affected by multiple vulnerabilities

2018-08-0304:23:43
www.ibm.com
29

EPSS

0.044

Percentile

92.5%

Summary

TXSeries for Multiplatforms has addressed the following vulnerabilities : CVE-2018-1426, CVE-2018-1427, CVE-2018-1428, CVE-2017-3736, CVE-2017-3732, CVE-2016-0705

Vulnerability Details

CVEID:CVE-2018-1426**
DESCRIPTION:*IBM GSKit duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material.
CVSS Base Score: 7.4
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/139071for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

CVEID:CVE-2018-1427 **DESCRIPTION:*IBM GSKit contains several environment variables that a local attacker could overflow and cause a denial of service.
CVSS Base Score: 6.2
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/139072for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID:CVE-2018-1428**
DESCRIPTION:*IBM GSKit uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVSS Base Score: 6.2
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/139073for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2017-3736**
DESCRIPTION:*OpenSSL could allow a remote attacker to obtain sensitive information, caused by a carry propagation flaw in the x86_64 Montgomery squaring function bn_sqrx8x_internal(). An attacker with online access to an unpatched system could exploit this vulnerability to obtain information about the private key.
CVSS Base Score: 5.9
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/134397for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2017-3732**
DESCRIPTION:*OpenSSL could allow a remote attacker to obtain sensitive information, caused by a carry propagating bug in the x86_64 Montgomery squaring procedure. An attacker could exploit this vulnerability to obtain information about the private key.
CVSS Base Score: 5.3
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/121313for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2016-0705**
DESCRIPTION:*OpenSSL is vulnerable to a denial of service, caused by a double-free error when parsing DSA private keys. An attacker could exploit this vulnerability to corrupt memory and cause a denial of service.
CVSS Base Score: 3.7
CVSS Temporal Score: Seehttps://exchange.xforce.ibmcloud.com/vulnerabilities/111140for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Aff****ected TXSeries for Multiplatforms

| Affected Versions
—|—
TXSeries for Multiplatforms | 9.1
TXSeries for Multiplatforms | 8.2
TXSeries for Multiplatforms | 8.1
TXSeries for Multiplatforms | 7.1

Remediation/Fixes

Product

| VRMF| APAR| Remediation / First Fix
—|—|—|—
TXSeries for Multiplatforms| 9.1.| The updated GSkit have been made available on FixCentral as a special fix

FixID : TXSeriesV91-SpecialFix_GSKit| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EOther%20software&product=ibm/WebSphere/TXSeries+for+Multiplatforms&release=9.1.0.0&platform=All&function=fixId&fixids=TXSeriesV91-SpecialFix_GSKit&includeSupersedes=0&source=fc
TXSeries for Multiplatforms| 8.2| The updated GSkit have been made available on FixCentral as FixPacks
AIX :
8.2.0.2-TXSeries-AIX-FixPack2

Linux x86 : 8.2.0.2-TXSeries-Linux-FixPack2

Windows : 8.2.0.2-TXSeries-WINDOWS-FixPack2

HPUX-IA64 : 8.2.0.2-TXSeries-HPUX-IA64-FixPack2| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EOther%20software&product=ibm/WebSphere/TXSeries+for+Multiplatforms&release=8.2.0.2&platform=All&function=all&source=fc
TXSeries for Multiplatforms| 8.1| The updated GSkit have been made available on FixCentral as a special fix

FixID :TXSeriesV81-SpecialFix_GSKit| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EOther%20software&product=ibm/WebSphere/TXSeries+for+Multiplatforms&release=8.1.0.0&platform=All&function=fixId&fixids=TXSeriesV81-SpecialFix_GSKit&includeSupersedes=0&source=fc
TXSeries for Multiplatforms| 7.1| The updated GSkit have been made available on FixCentral as a special fix

FixID :TXSeriesV71-SpecialFix_GSKit| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm%7EOther%20software&product=ibm/WebSphere/TXSeries+for+Multiplatforms&release=7.1.0.6&platform=All&function=fixId&fixids=TXSeriesV71-SpecialFix_GSKit&includeSupersedes=0&source=fc

Workarounds and Mitigations

none