IBM Support

Security Bulletin: Vulnerability in Apache Commons affects IBM Tivoli Storage Manager Operations Center (OC) and Client Management Services (CMS) (CVE-2015-7450)

Created by Rob Jose on
Published URL:
https://www.ibm.com/support/pages/node/272619
272619

Security Bulletin


Summary

An Apache Commons Collections vulnerability for handling Java object deserialization was addressed by IBM Tivoli Storage Manager Operations Center (IBM Spectrum Protect Operations Center) and IBM Tivoli Storage Manager Client Services (IBM Spectrum Protect Client Management Services)..

Vulnerability Details

CVEID: CVE-2015-7450
DESCRIPTION
: Apache Commons Collections could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of data with Java InvokerTransformer class. By sending specially crafted data, an attacker could exploit this vulnerability to execute arbitrary Java code on the system.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/107918 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM Tivoli Storage Manager Operations Center (Spectrum Protect Operations Center) V6.4 and V7.1

IBM Tivoli Storage Manager Client Management Services (Spectrum Protect Client Management Services) V7.1

Remediation/Fixes

Release

First Fixing VRMF LevelRemediation/First Fix
OC 6.4 *OC 6.4.2.300 ALL Operating Systems
OC 7.1OC 7.1.4.000 ALL Operating Systems
CMS 7.1CMS 7.1.4.000 ALL Operating Systems

* If the Operations Center is running on AIX, you must uninstall the Operations Center before you install the iFix. Instructions for uninstalling the Operations Center are available here:
http://www.ibm.com/support/knowledgecenter/SSGSG7_6.4.1/com.ibm.itsm.srv.install.doc/t_oc_inst_uninstalling.html?lang=en

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

12/10/2015 - Original Copy Published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSSQWC","label":"Tivoli Storage Manager Extended Edition"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"6.4;7.1","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
17 June 2018

UID

swg21971533