-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                              ESB-2012.1102.2
          Security vulnerability in theme component for WebSphere
                      Portal versions 7.0.0.x and 8.0
                              3 December 2012

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM WebSphere Portal
Publisher:         IBM
Operating System:  AIX
                   Linux variants
                   Solaris
                   Windows
Impact/Access:     Provide Misleading Information -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2012-4834  

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=swg21617713

Revision History:  December  3 2012: Added CVE reference
                   November 21 2012: Initial Release

- --------------------------BEGIN INCLUDED TEXT--------------------

Security vulnerability in theme component for WebSphere Portal versions 7.0.0.x
and 8.0

Flash (Alert)

Abstract
Security vulnerability in theme component for WebSphere Portal versions 7.0.0.x
and 8.0.

Content
A URL manipulation security vulnerability has been found in the theme
component for WebSphere Portal versions 7.0.0.x and 8.0.

APAR PM76354 has been provided to address this issue. The APAR is available as
an interim fix for WebSphere Portal 7.0.0.1 and 7.0.0.2 (scheduled to be
included in Cumulative Fix 19), and is integrated in Cumulative Fix 3 for
WebSphere Portal 8.0. Links to the respective fixes are included in the
Related information section below.

CVSS Score: 7.8.

Related information
8.0 Cumulative Fix 3
http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Portal&release=8.0.0.0&platform=All&function=aparId&apars=PM74094

7001 / 7002 Interim Fix
http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm~WebSphere&product=ibm/WebSphere/WebSphere+Portal&release=All&platform=All&function=aparId&apars=PM76354

Copyright and trademark information
IBM, the IBM logo and ibm.com are trademarks of International Business
Machines Corp., registered in many jurisdictions worldwide. Other product and
service names might be trademarks of IBM or other companies. A current list
of IBM trademarks is available on the Web at "Copyright and trademark
information" at www.ibm.com/legal/copytrade.shtml.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBULwdWe4yVqjM2NGpAQK4fRAAnb3bwET2eBPSrGHJl/pNVXVN55320syj
DkXgd1KHbD/4GvP6dWWpxOOV99hlfrQGa5mf193a/mqSLilxLpyMQmLD3IufYYC7
EZDkV7u0RZUL7tk2hADB0QLAohFQ2aOj68/S02pIxWP5GPDVpRuk3r+cUToAZuzt
Pzc5pLI0zArv+V2rtbHYXJfcBydNWGG2L0gsdkmUMjMTxyQMQ0qsnQO9WywagMuZ
rLylnZN+eHd4Bz8jdc9tPA2heAofhMZiOOEct76XoMRCNxbM3fB7CDqKV7VLQCNl
PEP5AJLHxNREOA7r/dNe4gTk5t2Yjfab3exYkKMY5Gh+2q9wr0MO0NKBTPNfQDNX
BwbDterQx31MZkiuSsxadLt1L36zssqp0OARR7M6b9G6aG+XIrRzdWgiEgjfPfVy
7Gjkw5Ku1HuyEGrs7Y0OPEayEwk/I1C3Zs/SeVArQhTY+GzuMBYDSbG4Dp+pahgh
GIZrXjGrd8tRErXROTTcgw4lJm3e0C7cNAYy5w/G4zOKy7EmnZ3CqFcqM2xjxNhF
hkJc8E+NoYCE1hgLPW5NTAoIYKp/ONhM+/WWywhhV543TKc6ekAwX2dOJ0B1ku2Z
F9w4mRADoVq27DoM9+LULydglr4wem/f7k9hJafO3OyTws9aG1gFQPN6TxzYo5ys
HzOZsWp6dZg=
=O9yd
-----END PGP SIGNATURE-----