Security Bulletin: Asset and Service Management Products - Potential security exposure with IBM WebSphere application server after installing fix for APAR PM44303 (CVE-2012-3325)
VULNERABILITY DETAILS:
**
CVE ID: CVE-2012-3325**
DESCRIPTION:
Customers that have installed a Websphere Application Server fix for APAR PM44303 or a fix pack containing PM44303, have the potential for an authenticated user to gain access to unauthorized resources.
CVSS:
CVSS Base Score: 6
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/77959>_ for the current score
CVSS Environmental Score*: Undefined
CVSS String: (AV:N/AC:M/Au:S/C:P/I:P/A:P)
VERSIONS AFFECTED:
The problem affects the following IBM WebSphere Application Server versions:
Version 6.1.0.43
Version 7.0.0.21 - 7.0.0.23
Version 8.0.0.2 - 8.0.0.4
Version 8.5.0.0
The problem does not occur on the following IBM WebSphere Application Server versions:
Version 6.1.0.0 - 6.1.0.41
Version 7.0.0.0 - 7.0.0.19
Version 8.0.0.0 - 8.0.0.1
IBM supplied Websphere Application Server with the following products. The versions that were bundled are not affected, but may have been upgraded to an affected version in your environment.
Maximo Asset Management, Maximo Industry Solutions, and Tivoli Asset Management for IT 6.2 bundled Websphere Application Server 6.0.
Maximo Asset Management, Maximo Industry Solutions, Tivoli Asset Management for IT, Tivoli Service Request Manager, and Tivoli Change and Configuration Management Database 7.1 and 7.2 bundled Websphere Application Server 6.1.
Maximo Asset Management and Maximo Industry Solutions 7.5 bundled Websphere Application Server 7.0.
SmartCloud Control Desk 7.5 bundled Websphere Application Server 7.0.
Intelligent Building Management 1.1 bundled Websphere Application Server 7.0.
TRIRIGA Application Platform 3.2 bundled Websphere Application Server 8.0.
REMEDIATION:
Determine the specific version of WebSphere that you have installed, then go to the Websphere Security Flash for PM71296 to download the appropriate Interim Fix or a Fix Pack containing this APAR. On this page the various Interim Fixes and Fix Packs are separated by the specific WebSphere version. Locate the version of WebSphere that matches your installed version and click the appropriate link to take you to the download page for the fix.
To Determine your WebSphere Version:
1. Access the Administrative Console for WebSphere. Sign into Console.
2. Locate the Welcome Page contains the WebSphere Application Server Version (in this example the version is 6.1.0.35):
(in this example the version is 6.0.2.43)
(in this example the version is 7.0.0.13)
REFERENCES:
Complete CVSS Guide
On-line Calculator V2
X-Force Vulnerability Database_ _
CVE-2012-3325
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _
**
Note: _**According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an โindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.โ IBM PROVIDES THE CVSS SCORES โAS ISโ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
05 Sep 2012| Flash published
CROSS REFERENCE INFORMATION:
Segment | Product | Component/Platform | Version |
---|---|---|---|
Systems and Asset Management | Maximo Asset Management | All | 6.2.0 โ 6.2.8 |
7.1.1.0 โ 7.1.1.11 | |||
7.5.0.0 โ 7.5.0.3 | |||
Systems and Asset Management | Maximo Asset Management Essentials | All | 7.1.1.0 โ 7.1.1.11 |
7.5.0.0 โ 7.5.0.3 | |||
Systems and Asset Management | Maximo Asset Management for Energy Optimization | All | 7.1.0.0 โ 7.1.1.0 |
Systems and Asset Management | Maximo for Government | All | 6.1.0.0 |
7.1.0.0 | |||
7.5.0.0 | |||
Systems and Asset Management | Maximo for Nuclear Power | All | 6.3.0 |
7.1.0.0 โ 7.1.1.0 | |||
7.5.0.0 | |||
Systems and Asset Management | Maximo for Transportation | All | 6.3.0 |
7.1.0.0 โ 7.1.1.0 | |||
7.5.0.0 | |||
Systems and Asset Management | Maximo for Life Sciences | All | 6.4.0 โ 6.5.0 |
7.1.0.0 โ 7.1.2.0 | |||
7.5.00 | |||
Systems and Asset Management | Maximo for Oil and Gas | All | 6.3.0 โ 6.4.0 |
7.1.0.0 โ 7.1.2.0 | |||
7.5.0.0 | |||
Systems and Asset Management | Maximo for Utilities | All | 6.3.0 |
7.1.0.0 โ 7.1.2.0 | |||
7.5.0.0 | |||
Systems and Asset Management | Tivoli Service Request Manager |
Maximo Service Desk| All| 7.1.0.0 โ 7.1.1.11
7.2.0.0 โ 7.2.1.4
6.2.0 โ 6.2.8
Systems and Asset Management| Tivoli Asset Management for IT | All| 6.2.0 โ 6.2.8
7.1.0.0 โ 7.1.1.11
7.2.0.0 โ 7.2.2.1
Systems and Asset Management| Change and Configuration Management Database| All| 7.1.0.0 โ 7.1.1.11
7.2.0.0 โ 7.2.1.3
Systems and Asset Management| SmartCloud Control Desk| All| 7.5.0.0 โ 7.5.0.1
Systems and Asset Management| TRIRIGA Application Platform| All| 3.2
[{โProductโ:{โcodeโ:โSSLKT6โ,โlabelโ:โIBM Maximo Asset Managementโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โโโ,โPlatformโ:[{โcodeโ:โPF025โ,โlabelโ:โPlatform Independentโ}],โVersionโ:โ6.2;6.2.1;6.2.2;6.2.3;6.2.4;6.2.5;6.2.6;6.2.7;6.2.8;7.1;7.1.1;7.1.2;7.2;7.2.1;7.5โ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSWK4Aโ,โlabelโ:โMaximo Asset Management Essentialsโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:" โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSU3T4โ,โlabelโ:โMaximo Asset Management for Energy Optimizationโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSMQTPโ,โlabelโ:โMaximo for Governmentโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSLL8Mโ,โlabelโ:โMaximo for Nuclear Powerโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSLL9Zโ,โlabelโ:โMaximo for Transportationโ},โBusiness Unitโ:{โcodeโ:โBU059โ,โlabelโ:โIBM Software w/o TPSโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSLL84โ,โlabelโ:โMaximo for Life Sciencesโ},โBusiness Unitโ:{โcodeโ:โBU059โ,โlabelโ:โIBM Software w/o TPSโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSLL9Gโ,โlabelโ:โMaximo for Oil and Gasโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSLLAMโ,โlabelโ:โMaximo for Utilitiesโ},โBusiness Unitโ:{โcodeโ:โBU059โ,โlabelโ:โIBM Software w/o TPSโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSS6HJKโ,โlabelโ:โTivoli Service Request Managerโ},โBusiness Unitโ:{โcodeโ:โBU053โ,โlabelโ:โCloud & Data Platformโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB36โ,โlabelโ:โIBM Automationโ}},{โProductโ:{โcodeโ:โSSLKTYโ,โlabelโ:โMaximo Asset Management for ITโ},โBusiness Unitโ:{โcodeโ:โBU053โ,โlabelโ:โCloud & Data Platformโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}},{โProductโ:{โcodeโ:โSSKTXTโ,โlabelโ:โTivoli Change and Configuration Management Databaseโ},โBusiness Unitโ:{โcodeโ:โBU053โ,โlabelโ:โCloud & Data Platformโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB45โ,โlabelโ:โAutomationโ}},{โProductโ:{โcodeโ:โSSWT9Aโ,โlabelโ:โIBM Control Deskโ},โBusiness Unitโ:{โcodeโ:โBU053โ,โlabelโ:โCloud & Data Platformโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โโ,โEditionโ:โโ,โLine of Businessโ:{โcodeโ:โLOB45โ,โlabelโ:โAutomationโ}},{โProductโ:{โcodeโ:โSSHEB3โ,โlabelโ:โIBM TRIRIGA Application Platformโ},โBusiness Unitโ:{โcodeโ:โBU055โ,โlabelโ:โCognitive Applicationsโ},โComponentโ:โ โ,โPlatformโ:[{โcodeโ:โโ,โlabelโ:โโ}],โVersionโ:โ3.2โ,โEditionโ:โ",โLine of Businessโ:{โcodeโ:โLOB02โ,โlabelโ:โAI Applicationsโ}}]