IBM Support

Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with multiple IBM Security products

Created by Jim Wade on

Security Bulletin


Summary

IBM WebSphere Application Server is shipped as a component of multiple IBM Security products. Information about a security vulnerability affecting these products has been published in a security bulletin.

Vulnerability Details

Please consult the security bulletin Classloader Manipulation Vulnerability in IBM WebSphere Application Server (CVE-2014-0114) for vulnerability details.

Affected Products and Versions

Principal Product and Versions

Affected Supporting Product and Version
IBM Security Access Manager for Enterprise Single Sign-On 8.1WebSphere Application Server Network Deployment 7.0
IBM Security Access Manager for Enterprise Single Sign-On 8.2WebSphere Application Server Network Deployment 7.0
IBM Security Access Manager for Enterprise Single Sign-On 8.2.1WebSphere Application Server Network Deployment 8.5
IBM Tivoli Identity Manager 5.0WebSphere Application Server - Base 6.1
WebSphere Application Server Network Deployment 7.0
IBM Tivoli Identity Manager 5.1WebSphere Application Server Network Deployment 6.1
WebSphere Application Server Network Deployment 7.0
IBM Security Identity Manager 6.0WebSphere Application Server Network Deployment 7.0
IBM Tivoli Access Manager for e-business 6.0, 6.1, 6.1.1
(Note: Version 5.1 is no longer supported. IBM recommends upgrading to a supported version of the product.)
WebSphere Application Server 6.1 and 7.0
IBM Tivoli Federated Identity Manager 6.1.1, 6.2.0, 6.2.1, 6.2.2WebSphere Application Server 6.1 and 7.0
IBM Tivoli Federated Identity Manager Business Gateway 6.1.1, 6.2.0, 6.2.1, 6.2.2WebSphere Application Server 6.1 and 7.0
IBM Tivoli Key Lifecycle Manager 1.0, 2.0, 2.0.1Websphere Application Server 6.1.0.0 through 6.1.0.47
IBM Tivoli Security Policy Manager 7.0, 7.1WebSphere Application Server 6.1 and 7.0
IBM Tivoli Directory Server 6.1embedded version of IBM WebSphere Application Server 6.1
IBM Tivoli Directory Server 6.2embedded version of IBM WebSphere Application Server 6.1
IBM Tivoli Directory Server 6.3embedded version of IBM WebSphere Application Server 7.0
IBM Security Directory Server 6.3.1embedded version of IBM WebSphere Application Server 7.0
IBM Tivoli Security Information and Event Manager 2.0.0.4, 2.0.0.5, 2.0.0.6, 2.0.0.7, 2.0.0.8, 2.0.0.9WebSphere Application Server 6.1.0.27

Get Notified about Future Security Bulletins

References

Off

Change History

3 June 2014 - Added IBM Tivoli Security Information and Event Manager

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SS9JLE","label":"IBM Security Access Manager for Enterprise Single Sign-On"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF033","label":"Windows"}],"Version":"8.1;8.2;8.2.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSRMWJ","label":"IBM Security Identity Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF010","label":"HP-UX"}],"Version":"6.0;5.1;5.0","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"","label":"All Platforms"}],"Version":"6.0;6.1;6.1.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSZSXU","label":"Tivoli Federated Identity Manager"},"Business Unit":{"code":"BU008","label":"Security"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"},{"code":"PF010","label":"HP-UX"}],"Version":"6.1.1;6.2;6.2.1;6.2.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SS4J57","label":"Tivoli Federated Identity Manager Business Gateway"},"Business Unit":{"code":"BU008","label":"Security"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"6.1.1;6.2;6.2.1;6.2.2","Edition":"","Line of Business":{"code":null,"label":null}},{"Product":{"code":"SSWPVP","label":"IBM Security Key Lifecycle Manager"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"","label":"Windows 2003 server"},{"code":"","label":"Windows 2008 server"},{"code":"PF035","label":"z\/OS"}],"Version":"1.0;2.0;2.0.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSNGTE","label":"Tivoli Security Policy Manager"},"Business Unit":{"code":"BU008","label":"Security"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"","label":"Linux xSeries"},{"code":"","label":"Linux zSeries"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"7.0;7.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSVJJU","label":"IBM Security Directory Server"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"","label":"All Platforms"}],"Version":"6.1;6.2;6.3;6.3.1","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
19 August 2022

UID

swg21674742