IBM Support

Security Bulletin: IBM Tivoli Access Manager - token authentication RSA SecurID library uses weak cryptography (CVE-2013-0941)

Created by Jim Wade on
Published URL:
https://www.ibm.com/support/pages/node/494155
494155

Security Bulletin


Summary

This bulletin applies to the WebSEAL component of Tivoli Access Manager for e-business (TAM) systems participating in token authentication. Earlier versions of the Authentication API provided by RSA used poor cryptography in generating keys which are used to encrypt communications between the WebSEAL system and the RSA Server when performing RSA SecurID token authentication.

Vulnerability Details


CVE-2013-0941

DESCRIPTION:
The WebSEAL component of TAM supports token authentication through integration with the RSA SecurId token authentication product. To support this integration, TAM includes an authentication module, commonly referred to as a "CDAS" module that includes a library provided by RSA. This library provides the client components of the RSA Authentication API that communicate with the RSA authentication server.

An updated library has been provided by RSA, which is included in the patched versions of IBM Tivoli Access Manager for e-business (TAM). After applying the patch, customers must remove existing node secret files from affected WebSEAL systems and regenerate them.

The attack requires administrative access to the file system of the WebSEAL server, and specialized knowledge and techniques to manipulate the file. An exploit would not impact accessibility of system resources, but it could affect the confidentiality of information and the integrity of some of the data used in the communications between the TAM WebSEAL system and the RSA authentication server.

CVE ID:
CVE-2013-0941

CVSS:
CVSS Base Score: 3.6
CVSS Temporal Score: See  https://exchange.xforce.ibmcloud.com/vulnerabilities/84319
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N)

Affected Products and Versions


· Tivoli Access Manager 5.1 (out of service)
· Tivoli Access Manager 6.0.0 versions before fixpack 29.
· Tivoli Access Manager 6.1.0 versions before fixpack 10.
· Tivoli Access Manager 6.1.1 versions before fixpack 6.

Remediation/Fixes

Customers using version 5.1 should upgrade to a supported version of the product.

Remediation consists of the following steps:
1. Patch server systems. RSA will be providing patches and instructions in a separate advisory. For more information, visit the below link (authentication required) (https://knowledge.rsasecurity.com/scolcms/set.aspx?id=9718).
2. Obtain and apply the patch for WebSEAL systems, referring to the "Vendor Fixes" chart at the end of this section.
3. IMPORTANT: Follow the instructions in the patch README file to replace any existing node secret files after the patch has been installed.



Vendor Fixes: Patches and installation instructions are provided at the URLs listed below.

FixBuildAPARDownload URL
6.1.1-ISS-AWS-FP0006120824IV30723http://www.ibm.com/support/docview.wss?uid=swg24033436
6.1.0-ISS-AWS-IF0010121030IV30727http://www.ibm.com/support/docview.wss?uid=swg24033715
6.0.0-ISS-AWS-IF0029121030IV30724http://www.ibm.com/support/docview.wss?uid=swg24033716


IMPORTANT: RSA has not provided an updated library for the AIX 5.1, Sparc Solaris 8, or HP 9000 operating systems. You will not be able to correct this vulnerability on that platform. You must instead migrate affected systems running the WebSEAL component of TAM to a different supported operating system that has the updated RSA library. Contact IBM Services for more information if you require assistance migrating.

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"5.1;6.0;6.1;6.1.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21638571