IBM Support

Security Bulletin: Vulnerabilities in OpenSSL and PHP affect IBM Tealeaf Customer Experience (CVE-2016-2107, CVE-2016-6290, CVE-2016-7125)

Created by Charles Hornig on
Published URL:
https://www.ibm.com/support/pages/node/554483
554483

Security Bulletin


Summary

OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM Tealeaf Customer Experience. IBM Tealeaf Customer Experience has addressed the applicable CVEs.
The IBM Tealeaf Customer Experience Passive Capture Application (PCA) component uses a version of PHP with reported security issues.

Vulnerability Details

CVEID: CVE-2016-2107
DESCRIPTION: OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error when the connection uses an AES CBC cipher and the server support AES-NI. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt traffic.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112854 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-6290
DESCRIPTION:
PHP could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in session.c. An attacker could exploit this vulnerability using vectors related to session deserialization to execute arbitrary code on the system.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115539 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2016-7125
DESCRIPTION:
PHP could allow a remote attacker to execute arbitrary code on the system, caused by the skipping of invalid session names that triggers incorrect parsing by ext/session/session.c. An attacker could exploit this vulnerability using control of a session name to inject and execute arbitrary code on the system.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/116958 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM Tealeaf Customer Experience v8.0-v9.0.2

Remediation/Fixes

Product

VRMF
Remediation/First Fix
IBM Tealeaf Customer Experience
9.0.2A
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2A_IBMTealeaf_PCA-3732-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.5224_9.0.2A_IBMTealeaf_CXUpgrade_FixPack3
IBM Tealeaf Customer Experience
9.0.2
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2_IBMTealeaf_PCA-3682-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.2.1223_IBMTealeaf_CXUpgrade_FixPack3
IBM Tealeaf Customer Experience
9.0.1A
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1A_IBMTealeaf_PCA-3724-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.5108_9.0.1A_IBMTealeaf_CXUpgrade_FixPack5
IBM Tealeaf Customer Experience
9.0.1
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1_IBMTealeaf_PCA-3673-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=9.0.1.1117_IBMTealeaf_CXUpgrade_FixPack5
IBM Tealeaf Customer Experience
9.0.0, 9.0.0A
You can contact the Technical Support team for guidance.
IBM Tealeaf Customer Experience
8.8
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.8_IBMTealeaf_PCA-3625-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.8.0.9049_IBMTealeaf_CXUpgrade_FixPack9
IBM Tealeaf Customer Experience
8.7
PCA: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.7_IBMTealeaf_PCA-3615-8_FixPack
Tealeaf CX: https://www.ibm.com/support/entry/portal/search_results?sn=spe&filter=keywords:ibmsupportfixcentralsearch&q=8.7.1.8847_IBMTealeaf_CXUpgrade_FixPack10
IBM Tealeaf Customer Experience
8.6 and earlier
You can contact the Technical Support team for guidance.
For v9.0.0, 9.0.0A, and versions before v8.7, IBM recommends upgrading to a later supported version of the product.
Note: A fix for CVE-2016-2108 was provided in OpenSSL versions 1.0.1o and 1.0.2c and was previously addressed by IBM Tealeaf Customer Experience.

Workarounds and Mitigations

Network access to the PCA system should be limited as much as possible.
You can contact the Technical Support team for further guidance.

Get Notified about Future Security Bulletins

References

Off

Change History

12 December 2016: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

Security Bulletin 76500 History
Submitted for review by Charles Hornig (chornig@us.ibm.com) at 14:33:01 on 10/12/2016.
Security Bulletin Reviewer review completed with comments ''''Security bulletin is for PR#s 80650, 76500 and 77430. The x-force link related to CVE-2016-2983 is not displaying the CVE details. X-force needs to check into that. This bulletin has been reviewed.'''' by Guncha Malik (gmalik@in.ibm.com) at 03:05:16 EST on 10/13/2016.
PSIRT Operations review completed with comments ''''This review by PSIRT Operations is now complete.'''' by Jennifer A. Davis (jendavis@us.ibm.com) at 18:35:27 EST on 10/16/2016.
Reviewing Attorney review completed with comments ''''Review complete'''' by VANESSA A. WITT (vanewitt@us.ibm.com) at 09:50:13 EST on 10/17/2016.
Security Bulletin Reviews Complete by deadmin (deadmin) at 09:50:15 EST on 10/17/2016.
Modified and submitted for review by Charles Hornig (chornig@us.ibm.com) at 09:54:49 on 11/21/2016.
Security Bulletin Reviewer review completed with comments ''review complete'' by Guncha Malik (gmalik@in.ibm.com) at 15:08:25 EST on 11/28/2016.
PSIRT Operations review completed with comments '''' by Joshua E. Dembling (jdemblin@us.ibm.com) at 15:30:22 EST on 11/28/2016.
Reviewing Attorney review completed with comments '''' by VANESSA A. WITT (vanewitt@us.ibm.com) at 15:55:57 EST on 11/28/2016.
Security Bulletin Reviews Complete by deadmin (deadmin) at 15:55:58 EST on 11/28/2016.

Security Bulletin 80650 History
Submitted for review by Charles Hornig (chornig@us.ibm.com) at 14:30:29 on 10/12/2016.
Security Bulletin Reviewer review completed with comments ''''Security bulletin is for PR#s 80650, 76500 and 77430. The x-force link related to CVE-2016-2983 is not displaying the CVE details. X-force needs to check into that. This bulletin has been reviewed.'''' by Guncha Malik (gmalik@in.ibm.com) at 02:53:02 EST on 10/13/2016.
PSIRT Operations review completed with comments ''''This review by PSIRT Operations is now complete.'''' by Jennifer A. Davis (jendavis@us.ibm.com) at 18:37:06 EST on 10/16/2016.
Reviewing Attorney review completed with comments ''''Review complete'''' by VANESSA A. WITT (vanewitt@us.ibm.com) at 09:56:54 EST on 10/17/2016.
Security Bulletin Reviews Complete by deadmin (deadmin) at 09:56:55 EST on 10/17/2016.
Modified and submitted for review by Charles Hornig (chornig@us.ibm.com) at 09:51:47 on 11/21/2016.
Security Bulletin Reviewer review completed with comments ''review complete'' by Guncha Malik (gmalik@in.ibm.com) at 14:47:47 EST on 11/28/2016.
PSIRT Operations review completed with comments '''' by Joshua E. Dembling (jdemblin@us.ibm.com) at 15:31:41 EST on 11/28/2016.
Reviewing Attorney review completed with comments '''' by VANESSA A. WITT (vanewitt@us.ibm.com) at 15:54:16 EST on 11/28/2016.
Security Bulletin Reviews Complete by deadmin (deadmin) at 15:54:18 EST on 11/28/2016.

Security Bulletin 84617 History
Submitted for review by Charles Hornig (chornig@us.ibm.com) at 10:01:32 on 11/21/2016.
Security Bulletin Reviewer review completed with comments ''review complete'' by Guncha Malik (gmalik@in.ibm.com) at 11:38:34 EST on 11/28/2016.
PSIRT Operations review completed with comments '''' by Joshua E. Dembling (jdemblin@us.ibm.com) at 15:32:37 EST on 11/28/2016.
Reviewing Attorney review completed with comments ''Review complete'' by VANESSA A. WITT (vanewitt@us.ibm.com) at 15:49:53 EST on 11/28/2016.
Security Bulletin Reviews Complete by deadmin (deadmin) at 15:49:54 EST on 11/28/2016.

[{"Product":{"code":"SSERNK","label":"Tealeaf Customer Experience"},"Business Unit":{"code":"BU055","label":"Cognitive Applications"},"Component":"--","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
16 June 2018

UID

swg21992307