IBM Support

Security Bulletin: Rational License Key Server Administration and Reporting Tool vulnerabilities (CVE-2014-3566, CVE-2014-4244)

Created by Pankaj Dwivedi on
Published URL:
https://www.ibm.com/support/pages/node/524643
524643

Security Bulletin


Summary

Two possible security vulnerabilities have been reported in RLKS Administration and Reporting Tool. There have been no reported exploits of these vulnerabilities.

Vulnerability Details

CVE ID: CVE-2014-3566

Description: Product could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and access the plaintext of encrypted connections.


CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97013 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVE ID: CVE-2014-4244

Description: An unspecified vulnerability in Oracle Java SE and JRockit related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact.

CVSS Base Score: 4

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/94605 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N)

Affected Products and Versions

This vulnerability impacts the following RLKS components and its releases:

  • RLKS Administration and Reporting Tool version 8.1.4
  • RLKS Administration and Reporting Tool version 8.1.4.2
  • RLKS Administration and Reporting Tool version 8.1.4.3
  • RLKS Administration and Reporting Tool version 8.1.4.4
  • RLKS Administration and Reporting Tool version 8.1.4.5
  • RLKS Administration Agent version 8.1.4
  • RLKS Administration Agent version 8.1.4.2
  • RLKS Administration Agent version 8.1.4.3
  • RLKS Administration Agent version 8.1.4.4

Note: This vulnerability has been fixed in RLKS Administration Agent version 8.1.4.5.

Remediation/Fixes

Replace the JRE used in RLKS Administration and Reporting Tool and IBM Rational License Key Server Administration Agent.

Steps to replace the JRE in RLKS Administration and Reporting Tool (All Versions)

  1. Go to Fix Central
  2. On the Find product tab, enter Rational Common Licensing in the Product Selector field and hit enter.
  3. Select the Installed Version and hit continue button.
  4. Select the platform of the machine where RLKS Administration and Reporting Tool is installed and hit continue button.
  5. On the Identify fixes page, select Browse for fixes and select Show fixes that apply to this version and hit continue button.
  6. Download the Java runtime iFix for RLKS Administration and Reporting Tool.

    Note: Although the name of the iFix is RLKS_Administration_And_Reporting_Tool_8145_Admin_iFix_1_<Platform>_<Architecture>, the same ifix is applicable to all previous RLKS Administration and Reporting Tool versions.
  7. Shutdown RLKS Administration and Reporting Tool.
  8. Go to the installation location of RLKS Administration and Reporting Tool.
  9. Rename <install location>/server/jre folder to <install location>/server/jre_back.
    This step backs up the existing JRE.
  10. Extract the downloaded JRE into <install location>/server/ folder
    Example: <install location>/server/jre
  11. Startup RLKS Administration and Reporting Tool.

  12. Login to the tool using rcladmin user and verify that you see the configured license servers under 'Server' tab.



Steps to replace the JRE in RLKS Administration Agent [Versions 8.1.4, 8.1.4.2, 8.1.4.3, 8.1.4.4]

This vulnerability has been fixed in RLKS Administration Agent 8.1.4.5. Upgrade the RLKS Administration Agent to version 8.1.4.5.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSTMW6","label":"Rational License Key Server"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"RLKS Administration and Reporting Tool","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.1.4.2;8.1.4.3;8.1.4.4;8.1.4.5","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
16 June 2018

UID

swg21695022