IBM Support

Security Bulletin: Public disclosed vulnerability from Nimbus-JOSE-JWT affects IBM Spectrum LSF

Created by Ji Shan Xing on
Published URL:
https://www.ibm.com/support/pages/node/873294
873294

Security Bulletin


Summary

Public disclosed vulnerability from Nimbus-JOSE-JWT affects IBM Spectrum LSF

Vulnerability Details

CVE-2017-16007 (BDSA-2017-0101)
Nimbus JOSE+JWT implemented the ECDH-ES encryption option of the 'JSON Web Encryption' standard in a way that is vulnerable to cryptanalysis. This would enable an attacker to determine the private key of the server, allowing them to recover or modify communications of other parties via a man-in-the-middle attack.
CVE-2017-12972
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different plaintext is obtained for the same HMAC.
CVE-2017-12974
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.

Affected Products and Versions

IBM Spectrum LSF 10.0.0.4
IBM Spectrum LSF 10.0.0.5
IBM Spectrum LSF 10.0.0.6
IBM Spectrum LSF 10.0.0.7

Remediation/Fixes

Remediation/Fixes

Product VRMF APAR Remediation / First Fix
LSF 10.1.0.4 None See fix below
LSF 10.1.0.5 None See fix below
LSF 10.1.0.6 None See fix below
LSF 10.1.0.7 None See fix below

Download Fix 512358 from the following location: 
http://www.ibm.com/support/fixcentral/swg/selectFixes?product=ibm/Other+software/IBM+Spectrum+LSF&release=All&platform=All&function=fixId&fixids=lsf-10.1-build512358&includeSupersedes=0 

1)    Go to the patch install directory: cd $LSF_ENVDIR/../10.1/install/ 

2)    Copy the patch file to the install directory $LSF_ENVDIR/../10.1/install/ 

3)    Run patchinstall: ./patchinstall <patch>

4)    Run "badmin mbdrestart"

Get Notified about Future Security Bulletins

References

Off

Change History

28 February 2019: Original version created

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSWRJV","label":"IBM Spectrum LSF"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
06 March 2019

UID

ibm10873294