Security Bulletin
Summary
Public disclosed vulnerability from Nimbus-JOSE-JWT affects IBM Spectrum LSF
Vulnerability Details
Nimbus JOSE+JWT implemented the ECDH-ES encryption option of the 'JSON Web Encryption' standard in a way that is vulnerable to cryptanalysis. This would enable an attacker to determine the private key of the server, allowing them to recover or modify communications of other parties via a man-in-the-middle attack.
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different plaintext is obtained for the same HMAC.
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
Affected Products and Versions
Remediation/Fixes
Remediation/Fixes
| Product | VRMF | APAR | Remediation / First Fix |
|---|---|---|---|
| LSF | 10.1.0.4 | None | See fix below |
| LSF | 10.1.0.5 | None | See fix below |
| LSF | 10.1.0.6 | None | See fix below |
| LSF | 10.1.0.7 | None | See fix below |
Download Fix 512358 from the following location:
http://www.ibm.com/support/fixcentral/swg/selectFixes?product=ibm/Other+software/IBM+Spectrum+LSF&release=All&platform=All&function=fixId&fixids=lsf-10.1-build512358&includeSupersedes=0
1) Go to the patch install directory: cd $LSF_ENVDIR/../10.1/install/
2) Copy the patch file to the install directory $LSF_ENVDIR/../10.1/install/
3) Run patchinstall: ./patchinstall <patch>
4) Run "badmin mbdrestart"
Get Notified about Future Security Bulletins
References
Change History
28 February 2019: Original version created
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
06 March 2019
UID
ibm10873294