IBM Support

PI64299: Installshield generates installation executables which are vulnerable DLL-planting vulnerability for .Net client

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • InstallShield generates installation executables which are
    vulnerable to an DLL-planting vulnerability during installation
    of the .NET client
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All WebSphere eXtreme Scale 8.6.0           *
    *                  customers                                   *
    *                  attempting to install the .NET client.      *
    ****************************************************************
    * PROBLEM DESCRIPTION: InstallShield generates installation    *
    *                      executables which are                   *
    *                      vulnerable to an DLL-planting           *
    *                      vulnerability during installation       *
    *                      of the .NET client                      *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    CVEID: CVE-2016-2542
    DESCRIPTION: Flexera InstallShield could allow a local
    attacker to gain elevated privileges on the system, caused by
    an untrusted search path. An attacker could exploit this
    vulnerability using a Trojan horse DLL in the current working
    directory of a setup-launcher executable file to gain elevated
    privileges on the system.
    CVSS Base Score: 7.8
    CVSS Temporal Score: See
    https://exchange.xforce.ibmcloud.com/vulnerabilities/110914
    for the current score
    CVSS Environmental Score*: Undefined
    CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    PI64299

  • Reported component name

    WS EXTREME SCAL

  • Reported component ID

    5724X6702

  • Reported release

    860

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2016-06-15

  • Closed date

    2016-09-28

  • Last modified date

    2016-09-28

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WS EXTREME SCAL

  • Fixed component ID

    5724X6702

Applicable component levels

  • R860 PSY

       UP

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSTVLU","label":"WebSphere eXtreme Scale"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"860","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 September 2016