-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2015.0181
  Security Bulletin: IBM OpenPages Platform with Database vulnerabilities
                              27 January 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM OpenPages
Publisher:         IBM
Operating System:  AIX
                   Windows
Impact/Access:     Access Privileged Data -- Remote/Unauthenticated
                   Modify Arbitrary Files -- Existing Account      
                   Delete Arbitrary Files -- Existing Account      
                   Denial of Service      -- Existing Account      
Resolution:        Patch/Upgrade
CVE Names:         CVE-2014-6455 CVE-2014-6454 CVE-2014-6453
                   CVE-2014-6452 CVE-2014-4310 CVE-2014-4300
                   CVE-2014-4299 CVE-2014-4298 CVE-2014-4297
                   CVE-2014-4296 CVE-2014-4295 CVE-2014-4294
                   CVE-2014-4293 CVE-2014-4292 CVE-2014-4291
                   CVE-2014-4290 CVE-2014-4289 CVE-2014-2478

Reference:         ASB-2014.0121

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=swg21690427

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: IBM OpenPages Platform with Database vulnerabilities.

Document information

More support for:

OpenPages GRC Platform

Software version:

6.2, 6.2.1, 7.0

Operating system(s):

AIX, Windows

Reference #:

1690427

Modified date:

2015-01-23

Security Bulletin

Summary

These security vulnerabilities exist in all versions of IBM OpenPages with 
Database: See Vulnerability Details for CVE IDs.

Vulnerability Details

Customers who have IBM OpenPages with Database are potentially impacted by 
these vulnerabilities.

CVE-ID: CVE-2014-6455

CVSS Base Score: 9.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97071 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component has complete confidentiality impact, complete integrity 
impact, and complete availability impact.


CVE-ID: CVE-2014-6453

CVSS Base Score: 9.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97069 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the Java VM Create
Session component has complete confidentiality impact, complete integrity 
impact, and complete availability impact.


CVE-ID: CVE-2014-6454

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97091 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-6452

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97090 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4310

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97081 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4300

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97089 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4299

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97088 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4298

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97087 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the SQLJ Create 
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4297

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97079 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4296

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97080 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4295

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97083 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the Java VM Create
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4294

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97084 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the Java VM Create
Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4293

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97075 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4292

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97076 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4291

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97077 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4290

CVSS Base Score: 4.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97078 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JPublisher 
Create Session component could allow a remote attacker to obtain sensitive 
information.


CVE-ID: CVE-2014-4289

CVSS Base Score: 3.600

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97093 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the JDBC Create 
Session component has partial confidentiality impact, partial integrity 
impact, and no availability impact.


CVE-ID: CVE-2014-2478

CVSS Base Score: 2.600

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/97094 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)

DESCRIPTION

An unspecified vulnerability in Oracle Database related to the Core RDBMS 
component could allow a remote attacker to obtain sensitive information.

Affected Products and Versions

IBM OpenPages with Database 6.2 through 7.0

Remediation/Fixes

A fix has been created for each affected version of the named product. 
Download and install the appropriate fix as soon as practicable. Fixes and 
installation instructions are provided at the URLs listed below:

Patch 					Download URL

IBM OpenPages with Database IF 3 	http://www.ibm.com/support/docview.wss?uid=swg24039227

Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product support 
alerts like this.

References

Complete CVSS Guide

On-line Calculator V2

Related information

IBM Secure Engineering Web Portal

IBM Product Security Incident Response Blog

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the 
Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVMcpOhLndAQH1ShLAQK0ZQ/+P/zdoBZ8mheKvo1Ox0jkQ+1KS5OYfwup
0nymAwy7fO1zl9blRTFQKUL4jt+byw5zUQcfqsSgLiWYHiLvAg1MuHzSXOudlDAI
Oof+1ymEAT+Vk9RH1IoHho/ObqrAWOVF7vpCG4p8x4ZWECdH6KKUkXLRIxzQRUjd
rNuTNmAHxtf7lhtVb5TYo+94PVklYJDD8Qr5JGLvAngPRoVAQUaa2ruHra19W875
rbMS0rWHfa26dXzr0hutnzHUsYrrJPw3WiYmcMqV4llQ9dr5NScUcO53jvIa2g4R
hRa4a513Jzt9OqIUHptqJp1AA+JhZ9Iqqusn5JL4xT339GMA3AA8JzPAzKef+Vod
oz+Qcg6pDiCFsJ1MuaAsBUx0FJ4o9Q2K7oM8xnRssmjvHblvhDAFHMJIbf4nw+ej
psQ5p3lIGgptsA2gjNyUu5yMgWSLV/O4MtaFdceLstaBSgMfqIOrhn8E3Ep0B7B2
p9MgmZkzsGFDoYgrmAvOaRz6G03HtZiCCmIEXUrsuVq/PCGsu5g0Ih8vLZaEEagE
BUTzXkGqt6izGCsVnpBesdz24EYd+X7eyx4A8c8/bpCHVfYUcWC13S4TuTqg6NKU
SA2sbCq+SkCsex1yV7M9aIxvAxqlgUrGTX+klfl3o1dwtzZMLIwbLRhYF4ihzU0S
/bpeTJ8U7NQ=
=QgAb
-----END PGP SIGNATURE-----