Multiple vulnerabilities exist in the Optim E-Business Console that can allow an attacker to view sensitive information, perform actions as an impersonated legitimate user, or upload, modify or delete web pages or scripts on the server.
VULNERABILITY DETAILS:
CVE ID:CVE-2013-0577
**DESCRIPTION:**A malicious user who has successfully authenticated can upload, modify or delete web pages or scripts in the Optim E-Business Console. An exploit will not impact accessibility of system resources or the confidentiality of information, but the integrity of the system could be compromised.
CVSS:
CVSS Base Score: 2.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83329 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:N/I:P/A:N)
CVE ID:CVE-2013-0579
**DESCRIPTION:**An attacker with access to a userβs open browser before the user authenticates with the Optim E-Business Console or a browser left open after the user has authenticated, regardless of how long, can gather information to allow the attacker to impersonate that user including viewing sensitive information and performing any actions as available to the impersonated user in any environment that can access to the Optim E-Business Console. An exploit will not impact accessibility of system resources but both the confidentiality of information and the integrity of the system and data could be compromised.
CVSS:
CVSS Base Score: 3.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83331 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:P/I:P/A:N)
CVE ID:CVE-2013-0580
**DESCRIPTION:**The Optim E-Business Console is vulnerable to cross-site request forgery which can allow an attacker to trick a legitimate user into opening a URL that results in an action being taken as that user, potentially without the knowledge of that user. Any actions taken require the user being tricked to either be previously authenticated or to authenticate as part of the attack. An exploit will not impact accessibility of system resources but both the confidentiality of information and the integrity of the system and data could be compromised.
CVSS:
CVSS Base Score: 2.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/83332 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:A/AC:M/AU:S/C:N/I:P/A:N)
AFFECTED PRODUCTS:
Versions 6.0 through 9.1 of IBM Infosphere Optim Data Growth for Oracle E-Business Suite are affected.
**REMEDIATION:**The recommended solution is to apply the fix as soon as possible.
Fix:
Apply iFix OEBS-07.01.02_09.01.00-017, located here:
Workaround(s) & Mitigations:
None known, apply fixes
REFERENCES:
Β· Complete CVSS Guide_ _
Β· On-line Calculator V2_ _
RELATED INFORMATION:
Β· IBM Secure Engineering Web Portal
Β· IBM Product Security Incident Response Blog
CHANGE HISTORY:
4-Oct-2013: Original version published
10-Oct-2013: Updated
_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _
_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an βindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.β IBM PROVIDES THE CVSS SCORES βAS ISβ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
[{βProductβ:{βcodeβ:βSSMLQ4β,βlabelβ:βIBM InfoSphere Optim Test Data Management Solutionβ},βBusiness Unitβ:{βcodeβ:βBU059β,βlabelβ:βIBM Software w/o TPSβ},βComponentβ:βData Growth Solution for Oracle E-business Suiteβ,βPlatformβ:[{βcodeβ:βPF002β,βlabelβ:βAIXβ},{βcodeβ:βPF010β,βlabelβ:βHP-UXβ},{βcodeβ:βPF012β,βlabelβ:βIBM iβ},{βcodeβ:βPF016β,βlabelβ:βLinuxβ},{βcodeβ:βPF027β,βlabelβ:βSolarisβ},{βcodeβ:βPF033β,βlabelβ:βWindowsβ},{βcodeβ:βPF035β,βlabelβ:βz/OSβ}],βVersionβ:β9.1;8.1;7.1.2;7.1.1;7.1.0;6.1;6.0.2;6.0β,βEditionβ:ββ,βLine of Businessβ:{βcodeβ:βLOB10β,βlabelβ:βData and AIβ}}]