IBM Support

Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with Tivoli Workload Scheduler (CVE-2017-1381)

Created by Paolo Salerno on
Published URL:
https://www.ibm.com/support/pages/node/297445
297445

Security Bulletin


Summary

IBM WebSphere Application Server is shipped as a component of  Tivoli Workload Scheduler. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

Please consult the security bulletin http://www-01.ibm.com/support/docview.wss?uid=swg22004792 for vulnerability details and information about fixes

Affected Products and Versions

IBM Workload Scheduler is potentially impacted by the listed vulnerability since it potentially affects secure communications between eWAS and subcomponents.

The affected version is:
Tivoli Workload Scheduler Distributed 8.6.0
Tivoli Dynamic Workload Console 8.6.0
Tivoli Workload Scheduler z/OS Connector 8.6.0

Remediation/Fixes

IBM has provided patches for all embedded WebSphere versions.

Follow the instructions in the link below to install the fixes for eWAS 7.0.0.39 that is embedded in TWS 8.6 fixpack 04 :

http://www-01.ibm.com/support/docview.wss?uid=swg22004792

For TWS 8.6 version, the fixes can be applied only on top of TWS 8.6 fixpack 04.

For unsupported versions, releases or platforms IBM recommends upgrading to a fixed, supported version/release/platform of the product.

Workarounds and Mitigations

none

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSGSPN","label":"IBM Workload Scheduler"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"WebSphere Application Server","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.6","Edition":"Edition Independent","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg22009089