IBM Support

Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM Tivoli Storage Productivity Center (CVE-2015-1927)

Security Bulletin


Summary

IBM WebSphere Application Server is shipped as a component of IBM Tivoli Storage Productivity Center. Information about a security vulnerability (CVE-2015-1927) affecting IBM WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

CVEID: CVE-2015-1927
DESCRIPTION:
IBM WebSphere Application Server could allow a remote attacker to gain elevated privileges on the system, caused by an application not having the correct serveServletsbyClassname setting. By a developer not setting the correct property, an attacker could exploit this vulnerability to gain unauthorized access.
CVSS Base Score: 6.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/102872 for the current score.
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P)

Affected Products and Versions

IBM WebSphere Application Server 8.0 contained in:

  • Tivoli Storage Productivity Center 5.1.0 through 5.1.1.9
  • Tivoli Storage Productivity Center 5.2.0 through 5.2.7


IBM WebSphere Application Server 7.0 contained in Tivoli Integrated Portal in:
  • Tivoli Storage Productivity Center 5.1.0 through 5.1.1.9


The versions listed above apply to all licensed offerings of Tivoli Storage Productivity Center, including IBM SmartCloud Virtual Storage Center Storage Analytics Engine.

Remediation/Fixes

The solution is to apply an appropriate Tivoli Storage Productivity Center fix maintenance for each named product and execute the manual steps listed below. The solution should be implemented as soon as practicable. Tivoli Storage Productivity Center has been renamed to IBM Spectrum Control starting with version 5.2.8 and is the continued maintenance path. If you cannot upgrade to Tivoli Storage Productivity Center or IBM Spectrum Control as listed in the table below, follow the alternate steps listed.

Note: It is recommended to have a current backup before applying any update procedure.



Tivoli Storage Productivity Center V5.2.x
Apply the Tivoli Storage Productivity Center fix maintenance as soon as practicable. (See Latest Downloads.)
Affected TPC VersionAPARFixed VersionAvailability
5.2.xIT128815.2.8December 2015

If you cannot upgrade to IBM Spectrum Control 5.2.8, you can follow a procedure to apply an IBM WebSphere Application Server interim fix to your existing server as noted here.


Tivoli Storage Productivity Center V5.1.x
Apply the Tivoli Storage Productivity Center fix maintenance as soon as practicable. (See Latest Downloads.)
Affected TPC VersionAPARFixed VersionAvailability
5.1.xIT128815.1.1.10

Additional steps must be completed in addition to applying 5.1.1.10 and are listed below this table.
Target February 2015

Additional procedure for Tivoli Storage Productivity Center 5.1.1.x:

This procedure should be completed as part of the remediation whether you upgrade Tivoli Storage Productivity Center or follow the alternative procedure below to apply an IBM WebSphere Application Server interim fix. Tivoli Integrated Portal embeds IBM WebSphere Application Server 7.0 and requires the corresponding fix:

  1. Download interim fix PI31622 for IBM WebSphere Application Server 7.0. Reference the IBM WebSphere Application Server security bulletin:
    http://www.ibm.com/support/docview.wss?uid=swg21959083
  2. Apply the WebSphere Application Server 7.0 interim fix PI31622 to Tivoli Integrated Portal using the preinstalled WAS Update Installer, located in the folder (example for Windows):
    ..\IBM\tipv2\WebSphereUpdateInstallerV7\


Alternate procedure for remediation of Tivoli Storage Productivity Center:
If you cannot upgrade to Tivoli Storage Productivity Center 5.1.1.10 or IBM Spectrum Control 5.2.8, you can follow the procedure below to apply an IBM WebSphere Application Server interim fix to your existing server. For Tivoli Storage Productivity Center 5.1.1.x, you must still follow the steps listed above to remediate the Tivoli Integrated Portal component.
  1. Download iterim fix PI31622 for IBM WebSphere Application Server 8.0:
    http://www-01.ibm.com/support/docview.wss?uid=swg21959083
  2. If IBM Installation Manager is not yet installed on the Tivoli Storage Productivity Center server system, download and install IBM Installation Manager. It is recommended to use the latest version.
  3. Launch IBM Installation Manager from the command line, specifying the Tivoli Storage productivity Center IMData directory. The following is an example for Windows:
    IBMIM.exe -dataLocation <TPC dir>\IMData
  4. From the IBM Installation Manager UI:
    1. Select 'File' -> 'Preferences'
    2. Click on 'Add repository'
    3. Select the directory containing the IBM WebSphere Application Server interim fix PI31622. Press 'OK'
    4. Choose the 'Update' icon
    5. Select the IBM WebSphere Application Server interim fix PI31622 and press 'Next'
    6. Verify the pre-installation summary is correct and select 'Update'

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

4 January 2016: Original Version Published
13 January 2016: Corrected affected and fixed versions for 5.1.x.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SS5R93","label":"IBM Spectrum Control"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"5.1;5.1.1;5.2;5.2.1;5.2.2;5.2.3;5.2.4;5.2.5;5.2.6;5.2.7","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
22 February 2022

UID

swg21973958