Lucene search

K
ibmIBMDB77FA682E1C424D5DC75EF1D7E867B818764A3DCA318FD78F7BB076B3F08B21
HistoryJul 30, 2019 - 9:50 p.m.

Security Bulletin:IBM Security Identity Adapters has released a fix in response to the OpenSSL vulnerabilities

2019-07-3021:50:34
www.ibm.com
19

EPSS

0.048

Percentile

92.9%

Summary

IBM has released the following a fix for IBM Security Identity Adapters in response to OpenSSL vulnerabilities (CVE-2018-0732, CVE-2018-0733, CVE-2018-0734, CVE-2018-0739 and CVE-2019-1559)

Vulnerability Details

CVEID: CVE-2018-0732
DESCRIPTION: OpenSSL is vulnerable to a denial of service, caused by the sending of a very large prime value to the client by a malicious server during key agreement in a TLS handshake. By spending an unreasonably long period of time generating a key for this prime, a remote attacker could exploit this vulnerability to cause the client to hang.
CVSS Base Score: 3.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/144658&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2018-0733
DESCRIPTION: OpenSSL could allow a remote attacker to bypass security restrictions, caused by the failure to properly compare byte values by the PA-RISC CRYPTO_memcmp() function used on HP-UX PA-RISC targets. An attacker could exploit this vulnerability to forge messages, some of which may be authenticated.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/140849&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2018-0734
DESCRIPTION: OpenSSL could allow a remote attacker to obtain sensitive information, caused by a timing side channel attack in the DSA signature algorithm. An attacker could exploit this vulnerability using variations in the signing algorithm to recover the private key.
CVSS Base Score: 3.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/152085&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2018-0739
DESCRIPTION: OpenSSL is vulnerable to a denial of service. By sending specially crafted ASN.1 data with a recursive definition, a remote attacker could exploit this vulnerability to consume excessive stack memory.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/140847 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVE-ID: CVE-2019-1559
DESCRIPTION: OpenSSL could allow a remote attacker to obtain sensitive information, caused by the failure to immediately close the TCP connection after the hosts encounter a zero-length record with valid padding. An attacker could exploit this vulnerability using a 0-byte record padding-oracle attack to decrypt traffic.
CVSS Base Score: 5.8
CVSS Temporal Score: <https://exchange.xforce.ibmcloud.com/vulnerabilities/157514&gt; for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Identity Adapters v6.x and v7.x - see Remediation/Fixes.

Remediation/Fixes

Adapter Name

| VRMF | First Fix | Passport Advantage Part Numbers
—|—|—|—
IBM Security Identity Adapter for Lotus Notes | v7.1.14 / v6.0.14 | v7.1.15 / v6.0.15 | CC2FUML / CC2GEM
IBM Security Identity Adapter for Microsoft SQL Server | v7.1.16 / v6.0.15 | v7.1.17 / v6.0.16 | CC2FYML / CC2GCML
IBM Security Identity Adapter for Windows Active Directory | v7.1.31 / v6.1.31 | v7.1.32 / v6.1.32 | CC2GGM / CC2FWM
IBM Security Identity Adapter for Windows Local Accounts | v7.1.18 / v6.0.18 | v7.1.19 / v6.0.10 | CC2FXML / CC2GDML
IBM Security Identity Adapter for RACF | v7.1.36 / v6.0.36 | v7.1.37 / v6.0.37 | CC2G7ML / CC2GKML
IBM Security Identity Adapter for Computer Associates TopSecret | v7.1.17 / v6.0.17 | v7.1.18 / v6.0.18 | CC2G5ML / CC2GLML
IBM Security Identity Adapter for Computer Associates ACF2 | v7.1.28 / v6.0.28 | v7.1.29 / v6.0.29 | CC2G6ML / CC2GJML

Workarounds and Mitigations

None