IBM Support

Security Bulletin: Multiple vulnerabilities affect Watson Explorer, Watson Content Analytics and Watson Explorer Content Analytics Studio (CVE-2017-10115, CVE-2017-10116)

Created by Asako Iwai on
Published URL:
https://www.ibm.com/support/pages/node/298631
298631

Security Bulletin


Summary

Security vulnerabilities have been identified in IBM® Runtime Environment Java™ Technology Edition that is used by Watson Explorer, Watson Content Analytics and Watson Explorer Content Analytics Studio.

Vulnerability Details

CVEID: CVE-2017-10115
DESCRIPTION:
An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JCE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128876 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID: CVE-2017-10116
DESCRIPTION:
An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Security component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128877 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

These vulnerabilities apply to the following products and versions:

Affected Product

Affected VersionsApplicable Vulnerabilities
Watson Explorer Foundational Components11.0.0.0 - 11.0.0.3, 11.0.1,
11.0.2, 11.0.2.1
CVE-2017-10115
CVE-2017-10116
Watson Explorer Foundational Components10.0.0.0 - 10.0.0.4CVE-2017-10115
CVE-2017-10116
Watson Explorer Foundational Components9.0.0.0 - 9.0.0.8CVE-2017-10115
CVE-2017-10116
Watson Explorer Foundational Components8.2 - 8.2-6CVE-2017-10115
CVE-2017-10116
IBM Watson Explorer Foundational Components Annotation Administration Console11.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
CVE-2017-10115
CVE-2017-10116
IBM Watson Explorer Foundational Components Annotation Administration Console10.0 - 10.0.0.4CVE-2017-10115
CVE-2017-10116
Watson Explorer Analytical Components11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
CVE-2017-10115
CVE-2017-10116
Watson Explorer Analytical Components10.0.00 - 10.0.0.4CVE-2017-10115
CVE-2017-10116
IBM Watson Content Analytics3.5.0.0 - 3.5.0.4CVE-2017-10115
CVE-2017-10116
IBM Watson Explorer Content Analytics Studio11.0.0.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
CVE-2017-10115
CVE-2017-10116

Remediation/Fixes

Follow these steps to upgrade to the required version of IBM Java Runtime.

The table reflects product names at the time the specified versions were released. To use the links to Fix Central in this table, you must first log in to the IBM Support Fix Central site at http://www.ibm.com/support/fixcentral/.

Affected ProductAffected VersionsRequired IBM Java RuntimeHow to acquire and apply the fix
IBM Watson Explorer Foundational Components11.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
JVM 8 SR4 FP10 or laterUpgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures.
IBM Watson Explorer Foundational Components10.0 - 10.0.0.4JVM 8 SR4 FP10 or later
  1. If you have not already installed, install V10.0 Fix Pack 4 (see the Fix Pack download document). If you upgrade to Version 10.0.0.4 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the IBM Java Runtime, Version 8 package for your edition (Standard, Enterprise, or Advanced) and operating system from Fix Central: interim fix 10.0.0.4-WS-WatsonExplorer-<Edition>Foundational-<OS>-8SR4FP10 or later (for example, 10.0.0.4-WS-WatsonExplorer-EEFoundational-Linux-8SR4FP10).
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
IBM Watson Explorer9.0 - 9.0.0.8JVM 7.1 SR4 FP10 or later
  1. If you have not already installed, install Version 9.0 Fix Pack 8 (see Fix Central to download Version 9.0.0.8 Standard Edition or Enterprise Edition). If you upgrade to Version 9.0.0.8 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the IBM Java Runtime, Version 7 package for your edition and operating system from Fix Central: Interim fix 9.0.0.8-WS-WatsonExplorer-<Edition>-<OS>-7.1SR4FP10 or later (for example, 9.0.0.8-WS-WatsonExplorer-EE-Linux-7.1SR4FP10).
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
IBM InfoSphere Data Explorer8.2 - 8.2-6JVM 7.1 SR4 FP10 or later
  1. If you have not already installed, install V8.2 Fix Pack 6 (see Fix Central to download V8.2-6). If you upgrade to Version 8.2-6 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the IBM Java Runtime, Version 7 package for your operating system from Fix Central: Interim fix 8.2-6-WS-DataExplorer-<OS>-7.1SR4FP10 or later (for example, 8.2-6-WS-DataExplorer-Windows-7.1SR4FP10).
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
IBM Watson Explorer Foundational Components Annotation Administration Console11.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
JVM 8 SR4 FP10 or laterUpgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures.
IBM Watson Explorer Foundational Components Annotation Administration Console10.0 - 10.0.0.4JVM 7 SR10 FP10 or later
  1. If you have not already installed, install V10.0 Fix Pack 4 (see the Fix Pack download document). If you upgrade to Version 10.0.0.4 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the 32-bit and 64-bit packages of IBM Java Runtime, Version 7 for IBM Watson Explorer Advanced Edition and your operating system from Fix Central: interim fix
    10.0.0.4-WS-WatsonExplorer-AEFoundationallAAC-<OS>[32]-7SR10FP10 or later (for example, 10.0.0.4-WS-WatsonExplorer-AEFoundationalAAC-Linux32-7SR10FP10 and 10.0.0.4-WS-WatsonExplorer-AEFoundationalAAC-Linux-7SR10FP10).
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
IBM Watson Explorer Analytical Components11.0 - 11.0.0.3,
11.0.1,
11.0.2, 11.0.2.1
JVM 8 SR4 FP10 or laterUpgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures.
IBM Watson Explorer Analytical Components10.0 - 10.0.0.2JVM 7 SR10 FP10 or later
  1. If you have not already installed, install V10.0 Fix Pack 2 (see the Fix Pack download document). If you upgrade to Version 10.0.0.2 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the 32-bit (or 31-bit, if you use Linux on System z) and 64-bit packages of IBM Java Runtime, Version 7 package for your edition (Enterprise or Advanced) and operating system from Fix Central: interim fix 10.0.0.2-WS-WatsonExplorer-<Edition>Analytical-<OS>[32|31]-7SR10FP10 or later. For example, 10.0.0.2-WS-WatsonExplorer-AEAnalytical-Linux-7SR10FP10 and 10.0.0.2-WS-WatsonExplorer-AEAnalytical-Linux32-7SR10FP10.
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
  4. Rename $ES_INSTALL_ROOT/lib/activation.jar
    to activation.jar.orig if the file exists.
IBM Watson Content Analytics3.5 - 3.5.0.4JVM 7 SR10 FP10 or later
  1. If you have not already installed, install V3.5 Fix Pack 4 (see the Fix Pack download document). If you upgrade to Version 3.5.0.4 after you update IBM Java Runtime, your changes are lost and you must repeat the steps.
  2. Download the 32-bit (or 31-bit, if you use Linux on System z) and 64-bit packages of IBM Java Runtime, Version 7 package for your operating system from Fix Central: interim fix 3.5.0.4-WT-WCA-<OS>[32|31]-7SR10FP10 or later. For example, 3.5.0.4-WT-WCA-Linux-7SR10FP10 and 3.5.0.4-WT-WCA-Linux32-7SR10FP10.
  3. To apply the fix, follow the steps in Updating IBM Java Runtime.
  4. Rename $ES_INSTALL_ROOT/lib/activation.jar
    to activation.jar.orig if the file exists.
IBM Watson Explorer Content Analytics Studio11.0 - 11.0.0.3,
11.0.1
JVM 8 SR4 FP10 or laterIf you have not already installed, upgrade to Version 11.0.2.2.
IBM Watson Explorer Content Analytics Studio11.0.2, 11.0.2.1JVM 8 SR4 FP10 or laterUpgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures.

Get Notified about Future Security Bulletins

References

Off

Change History

4 Dec 2017 Updated to suggest upgrading to 11.0.2.2 for Version 11.
17 Nov 2017 Updated Version 11 entries
6 Nov 2017 Initially published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

4 Dec 2017 : Updated

Nov.17.2017 : Got deviation for 11.0.2.1 but some PMRs were coming from the customer, so tested with 8.0.4.11 and republished with information for V11.0.2.1 FC/AC/CAStudio.

Oct.24.2017 : initial draft is created, but V11 will be fixed in next Fix Pack, targeting Dec.2017. Need deviation on this.

[{"Product":{"code":"SS8NLW","label":"IBM Watson Explorer"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"10.0.0;11.0.0;11.0.1;8.2.0;9.0.0;11.0.2","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
17 June 2018

UID

swg22009912