IBM Support

Security Bulletin: Multiple vulnerabilities in current IBM SDK for Java for IBM Support Assistant April 2014 CPU

Created by Andrew Cook on

Security Bulletin


Summary

Multiple security vulnerabilities exist in the IBM® SDK for Java™ that is shipped with IBM Support Assistant

Vulnerability Details

The IBM Support Assistant Team Server is shipped with an IBM SDK for Java that is based on the Oracle JDK. Oracle has released April 2014 critical patch updates (CPU) which contain security vulnerability fixes. The IBM SDK for Java has been updated to incorporate these fixes.

CVEID: CVE-2014-0878
DESCRIPTION:
 A vulnerability in the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers potentially allows an attacker to predict the output of the random number generator under certain circumstances.
CVSS Base Score: 5.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/91084 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N) 

CVEID:
 CVE-2014-0460
DESCRIPTION:
 An unspecified vulnerability related to the JNDI component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 5.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/92482 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVEID: CVE-2014-0453

DESCRIPTION: An unspecified vulnerability related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/92490 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N) 

The following advisories are included in the SDK but IBM Support Assistant Team Server is not vulnerable to them. Please refer to the Reference section for more information on the advisories not applicable to IBM Support Assistant Team Server: 
CVE IDs:
 CVE-2014-0457 CVE-2014-2421 CVE-2014-0429 CVE-2014-0461 CVE-2014-0455 CVE-2014-2428 CVE-2014-0448 CVE-2014-0454 CVE-2014-0446 CVE-2014-0452 CVE-2014-0451 CVE-2014-2402 CVE-2014-2423 CVE-2014-2427 CVE-2014-0458 CVE-2014-2414 CVE-2014-2412 CVE-2014-2409 CVE-2013-6954 CVE-2013-6629 CVE-2014-2401 CVE-2014-0449 CVE-2014-0459 CVE-2014-2398 CVE-2014-1876 CVE-2014-2420

Affected Products and Versions

SDK shipped with IBM Support Assistant Team Server 5.0.0

Remediation/Fixes

Apply fixpack 5.0.1 to IBM Support Assistant. See the IBM Support Assistant 5.0.1 technote for more information on applying this fixpack

Workarounds and Mitigations

none

Get Notified about Future Security Bulletins

References

Off

Change History

30 May 2014: original document published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSLLVC","label":"IBM Support Assistant"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Team Server","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"5.0","Edition":"TeamServer","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
15 June 2018

UID

swg21674778