Lucene search

K
ibmIBM7046138B9599A1C4F494C484A9BB676F47CE5DB50FD7EC9400CB6F191317A8B0
HistoryOct 21, 2020 - 6:22 p.m.

Security Bulletin: Insecure Transmission Vulnerability with IBM InfoSphere Information Server (CVE-2015-7490)

2020-10-2118:22:30
www.ibm.com
113
ibm infosphere information server
user cookie
access control
vulnerability
version 8.5
version 8.7
version 9.1
version 11.3
version 11.5
security patch

EPSS

0.97

Percentile

99.8%

Summary

IBM InfoSphere Information Server could allow a malicious user who can login in IIS using their own user id to change the user cookie to another user id to possibly gain access to information that the other user id had access to.

Vulnerability Details

CVEID: CVE-2015-7490
DESCRIPTION: IBM InfoSphere Information Server could allow a malicious user who can login in IIS using their own user id to change the user cookie to another user id to possibly gain access to information that the other user id had access to.
CVSS Base Score: 3.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/108786&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

The following product, running on all supported platforms, is affected:
IBM InfoSphere Information Server: versions 8.5, 8.7, 9.1, 11.3, and 11.5

Remediation/Fixes

Product

| VRMF |APAR|Remediation/First Fix
—|—|—|—
InfoSphere Information Server | 11.5 | JR54787 | --Apply IBM InfoSphere Information Server version 11.5.0.1
InfoSphere Information Server | 11.3 | JR54787 | --Apply IBM InfoSphere Information Server version _11.3.1.2 _
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 9.1 | JR54787 | --Apply IBM InfoSphere Information Server version 9.1.2.0
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 8.7 | JR54787 | --Apply IBM InfoSphere Information Server version 8.7 Fix Pack 2
--Apply IBM InfoSphere Information Server Framework Security Patch
InfoSphere Information Server | 8.5 | JR54787 | --Apply IBM InfoSphere Information Server version 8.5 Fix Pack 3
--Apply IBM InfoSphere Information Server Framework Security Patch

Note: The same fix may be listed under multiple vulnerabilities. Installing the fix addresses all vulnerabilities to which the fix applies. Also, some fixes require installing both a fix pack and a subsequent patch. While the fix pack must be installed first, any additional patches required may be installed in any order.

Workarounds and Mitigations

None