Lucene search

K
ibmIBMD868E630F7E8A00E8BBAFBD402439B2118E449A42A585EF8C5DEAAE4F54ADBF1
HistoryJun 16, 2018 - 9:49 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by a vulnerability due to improper content validation (CVE-2016-3020)

2018-06-1621:49:22
www.ibm.com
8

EPSS

0.002

Percentile

60.0%

Summary

IBM Security Access Manager appliances could allow a remote attacker to bypass security restrictions, caused by improper content validation.

Vulnerability Details

CVEID: CVE-2016-3020**
DESCRIPTION:** IBM Security Access Manager for Web could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content.
CVSS Base Score: 3.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114465 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 7.0 (appliance) IV90718 Apply Interim Fix 28:
7.0.0-ISS-WGA-IF0028
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.4 IV90683 Upgrade to 8.0.1.5:
8.0.1-ISS-WGA-FP0005
IBM Security Access Manager for Mobile 8.0.0.0 -
8.0.1.4 IV90703 Upgrade to 8.0.1.5:
8.0.1-ISS-ISAM-FP0005
IBM Security Access Manager 9.0 -
9.0.2.0 IV90502 Upgrade to 9.0.2.1:
9.0.2-ISS-ISAM-FP0001

Workarounds and Mitigations

None.

EPSS

0.002

Percentile

60.0%

Related for D868E630F7E8A00E8BBAFBD402439B2118E449A42A585EF8C5DEAAE4F54ADBF1