Download
Abstract
Web Services requests (either JAX-RPC or JAX-WS) containing data encrypted by WS-Security can be decrypted by way of a decryption attack.
Download Description
PM34841 resolves the following problem:
ERROR DESCRIPTION:
Web Services requests (either JAX-RPC or JAX-WS) containing data encrypted by WS-Security can be decrypted by way of a decryption attack.
LOCAL FIX:
PROBLEM SUMMARY
USERS AFFECTED:
All users of IBM WebSphere Application Server using web services and WS-Security XML excryption
PROBLEM DESCRIPTION:
Potential security exposure with IBM WebSphere Application Server with Web Services using XML Encryption
If Web Service requests (either JAX-WS or JAX-RPC) containing encrypted data can be intercepted, then the encrypted information can be decrypted using an attack based on XML Encryption. All versions of JAX-RPC and JAX-WS are vulnerable.
RECOMMENDATION:
Install a fix pack which contains this APAR and set the specified JVM property.
PROBLEM CONCLUSION:
Applying Interim Fix APAR PM34841 or a Fix Pack containing one of these APARs, and enabling the update by setting a JVM custom property, resolves this issue. For IBM WebSphere Application Server Versions after 6.1.0.37 or 7.0.0.15, an update does not need to be installed, but it must be enabled by setting a custom JVM property, which resolves this issue.
When the update is enabled by setting the JVM custom property, detailed information may be removed from any SOAPFault generated by the Web Service runtimes. Note that the update is not enabled by default in order to maintain application compatibility with respect to SOAPFaults.
To enable the update, the following JVM custom property must be set after the update is installed: webservices.unify.faults=true . This property can be set using the administrative console as described in the Information Center article "Java virtual machine custom properties"
The fix for this APAR is currently targeted for inclusion in fix pack 6.1.0.39 and 7.0.0.17. Please refer to the Recommended Updates
Page for delivery information:
http://www.ibm.com/support/docview.wss?uid=swg27004980
Prerequisites
Download the UpdateInstaller below to install this fix.
Installation Instructions
Please review the readme.txt for detailed installation instructions.
Technical Support
Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the WebSphere Application Server support web site (http://www.ibm.com/support/entry/portal/Overview/Software/WebSphere/WebSphere_Application_Server), or contact 1-800-IBM-SERV (U.S. only).
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg24029632