IBM Security Access Manager for Web is affected by a vulnerability in the processing of HTTPTransformation requests in WebSEAL. This vulnerability could allow a remote attacker to gain access to readable/writable files on the system.
CVEID: CVE-2015-4963** **
DESCRIPTION: IBM Security Access Manager for Web could allow a remote attacker to gain access to readable/writable files on the system.
CVSS Base Score: 4.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105566 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)
IBM Security Access Manager for Web 7.0 software, all releases
IBM Security Access Manager for Web 7.0 appliance, all firmware releases
IBM Security Access Manager for Web 8.0, all firmware releases
The table below provides links to patches for all affected IBM Security Access Manager for Web versions. Follow the installation instructions in the README file included with the patch.
Product | VRMF | APAR | Remediation |
---|---|---|---|
IBM Security Access Manager for Web | |||
(software-installation) | 7.0.0.0 - | ||
7.0.0.15 | IV71196 | Apply the 7.0.0.16 interim fix: | |
7.0.0-ISS-SAM-IF0016 | |||
IBM Security Access Manager for Web | |||
(appliance-based) | _7.0.0.0 - | ||
7.0.0.15_ | IV71196 | Apply the 7.0.0.16 interim fix:_ | |
_7.0.0-ISS-WGA-IF0016 | |||
IBM Security Access Manager for Web | _8.0.0.1 - | ||
8.0.1.3_ | IV71196 | Upgrade to the 8.0.1.3 interim fix: | |
8.0.1.3-ISS-WGA-IF0001 |