Lucene search

K
ibmIBMC1B502738DE589E53B108D5D527E9C46BFC55701DA041F99A957ADA7D1790B2D
HistoryJan 10, 2020 - 8:09 a.m.

Security Bulletin: IBM WebSphere Cast Iron Solution & App Connect Professional is affected by Open Source vulnerabilities

2020-01-1008:09:09
www.ibm.com
16

EPSS

0.001

Percentile

34.4%

Summary

IBM WebSphere Cast Iron Solution & App Connect Professional has addressed the open source vulnerabilities.

Vulnerability Details

CVEID:CVE-2019-12749
**DESCRIPTION:**dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
CVSS Base score: 9.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/162386 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

WebSphere Cast Iron v 7.5.0.0, 7.5.0.1, 7.5.1.0

WebSphere Cast Iron v 7.0.0.0, 7.0.0.1, 7.0.0.2

App Connect Professional v 7.5.2.0

App Connect Professional v 7.5.3.0

Remediation/Fixes

Product VRMF Remediation/First Fix
IBM Cast Iron 7.0.0.0
7.0.0.1
7.0.0.2 7002 Fixcentral Link
IBM Cast Iron 7.5.0.0
7.5.0.1
7.5.1.0 7510 fixcentral Link
App Connect Professional 7.5.2.0 7520 Fixcentral link
App Connect Professional 7.5.3.0 7530 Fixcentral link

Workarounds and Mitigations

None