Lucene search

K
ibmIBMAD181883987A105E6A1E2ADDC4FD3E2991D4F349D55691E0738355588F063760
HistoryMar 23, 2020 - 8:41 p.m.

Security Bulletin: WebSphere Message Broker and IBM Integration Bus are affected by Open Source Tomcat vulnerability (CVE-2015-5346 )

2020-03-2320:41:52
www.ibm.com
11

0.009 Low

EPSS

Percentile

83.2%

Summary

WebSphere Message Broker and IBM Integration Bus are affected by Open Source Apache Tomcat vulnerability.

Vulnerability Details

CVEID: CVE-2015-5346**
DESCRIPTION:** Apache Tomcat could allow a remote attacker to hijack a valid user’s session, caused by the failure to recycle the requestedSessionSSL field when recycling the Request object to use for a new request. By persuading a victim to visit a specially-crafted link and log into the application, a remote attacker could exploit this vulnerability to hijack another user’s account and possibly launch further attacks on the system.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110854 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Integration Bus V10.0 & V9.0

WebSphere Message Broker V8.0

Remediation/Fixes

Product

| VRMF|APAR|Remediation/Fix
—|—|—|—
IBM Integration Bus| V10
| IT14053 | An interim fix is available from IBM Fix Central for all platforms.
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/Integration+Bus&release=All&platform=All&function=aparId&apars=IT14053

The APAR is targeted to be available in fix pack 10.0.0.6
IBM Integration Bus| V9
| IT14053 | An interim fix is available from IBM Fix Central for all platforms.
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/Integration+Bus&release=All&platform=All&function=aparId&apars=IT14053

The APAR is targeted to be available in fix pack 9.0.0.6
WebSphere Message Broker
| V8
| IT14053 | An interim fix is available from IBM Fix Central for all platforms.
http://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibms~WebSphere&product=ibm/WebSphere/WebSphere+Message+Broker&release=All&platform=All&function=aparId&apars=IT14053

The APAR is targeted to be available in fix pack 8.0.0.8.

For unsupported versions of the product, IBM recommends upgrading to a fixed, supported version/release/platform of the product.

The planned maintenance release dates for WebSphere Message Broker and IBM Integration Bus are available at :

http://www.ibm.com/support/docview.wss?rs=849&uid=swg27006308

Workarounds and Mitigations

None known