IBM Support

Security Bulletin: Multiple Websphere Vulnerabilities Impact IBM Control Center (CVE-2018-3169, CVE-2014-7810, CVE-2018-1767)

Security Bulletin


Summary

There are multiple vulnerabilities in Websphere that is used by Control Center.

Vulnerability Details

CVEID: CVE-2018-3169 (refer to CVE-2018-10237)
DESCRIPTION: Google Guava is vulnerable to a denial of service, caused by improper eager allocation checks in the AtomicDoubleArray and CompoundOrdering class. By sending a specially-crafted data, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/142508 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/ AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
DESCRIPTION: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on.
CVSS Base Score: 6.1
CVSS Temporal Score: See  https://exchange.xforce.ibmcloud.com/vulnerabilities/10315 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/ AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
 
DESCRIPTION: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621 .
CVSS Base Score: 6.1
CVSS Temporal Score: See  https://exchange.xforce.ibmcloud.com/vulnerabilities/148621 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/ AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM Control Center 6.0.0.0 through 6.0.0.2 iFix05
IBM Control Center 6.1.0.0 through 6.1.2.0 iFix01
 

Remediation/Fixes

Product

VRMF

iFix

APAR

Remediation / First Fix

IBM Control Center

6.0.0.2

iFix06

IT28715 / IT28716

Fix Central - 6.0.0.2

IBM Control Center

6.1.2.0

iFix02

IT28715 / IT28716

Fix Central - 6.1.2.0

Workarounds and Mitigations

None.

Get Notified about Future Security Bulletins

References

Off

Change History

16 April 2019: Original Document Published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

[{"Business Unit":{"code":"BU038","label":"Aricent Technologies"},"Product":{"code":"SS9GLA","label":"IBM Control Center"},"Component":"","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"All Versions","Edition":""}]

Document Information

Modified date:
17 December 2019

UID

ibm10881456