IBM Support

Security Bulletin: Apache HttpComponents vulnerable to spoofing attacks are affecting Case Manager Client (CVE-2012-6153, CVE-2014-3577)

Created by Wayne Chen on

Security Bulletin


Summary

Apache HttpComponents that are vulnerable to spoofing attacks are affecting Case Manager Client.

Vulnerability Details


Apache HttpComponents that are being utilized by the Forms widget in Case Manager Client when you are working with IBM Forms are vulnerable to spoofing attacks.

CVEID: CVE-2012-6153

DESCRIPTION:
Apache HttpComponents could allow a remote attacker to conduct spoofing attacks, caused by an incomplete fix related to the failure to verify that the server hostname matches a domain name in the Subject's Common Name (CN) or SubjectAltName field of certificates. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/95328 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVEID: CVE-2014-3577

DESCRIPTION: Apache HttpComponents could allow a remote attacker to conduct spoofing attacks, caused by the failure to verify that the server hostname matches a domain name in the Subject's Common Name (CN) or SubjectAltName field of certificates. By persuading a victim to visit a Web site containing a specially-crafted certificate, an attacker could exploit this vulnerability using man-in-the-middle techniques to spoof an SSL server.

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/95327 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

IBM Case Manager 5.1.1.0 - 5.1.1.2
IBM Case Manager 5.2.0.0 - 5.2.0.3
IBM Case Manager 5.2.1.0 - 5.2.1.2

Remediation/Fixes

Product

VRMF
APAR
Remediation/First Fix
IBM Case Manager5.2.1.3-FP003PJ438275.2.1.3-ICM-FP003
or later versions
IBM Case Manager5.2.0.4-FP004PJ441675.2.0.4-ICM-FP004
or later versions
IBM Case Manager5.1.1.3-IF002PJ438865.1.1.3-ICM-IF002
or later versions

IBM Forms APAR LO85829 - http://www.ibm.com/support/docview.wss?uid=swg21961713

IBM WebSphere APAR PI50993 - http://www.ibm.com/support/docview.wss?uid=swg24041394

For the complete fix, all of the above components need to be patched accordingly.

Get Notified about Future Security Bulletins

References

Off

Change History

27 June 2016: Modified Remediation /Fixes
24 February 2016: Modified Affected Products and Versions
19 February 2016: Modified Affected Products and Versions
30 December 2015: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSCTJ4","label":"IBM Case Manager"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Case Manager Client","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"5.2.1;5.2.0;5.1.1","Edition":"All Editions","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg21964916