-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2015.1169
  Security Bulletin: IBM OpenPages Platform with Database vulnerabilities
                               29 April 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM OpenPages with Database
Publisher:         IBM
Operating System:  AIX
                   Windows
Impact/Access:     Execute Arbitrary Code/Commands -- Existing Account
                   Modify Arbitrary Files          -- Existing Account
                   Denial of Service               -- Existing Account
                   Access Confidential Data        -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2015-0373 CVE-2015-0371 CVE-2015-0370
                   CVE-2014-6578 CVE-2014-6577 CVE-2014-6567
                   CVE-2014-6541 CVE-2014-6514 

Reference:         ASB-2015.0009

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=swg21883820

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: IBM OpenPages Platform with Database vulnerabilities

Document information

More support for:

OpenPages GRC Platform

Software version:

6.2, 6.2.1, 7.0

Operating system(s):

AIX, Windows

Reference #:

1883820

Modified date:

2015-04-28

Security Bulletin

Summary

These security vulnerabilities exist in all versions of IBM OpenPages with 
Database: See Vulnerability Details for CVE IDs.

Vulnerability Details

Customers who have IBM OpenPages with Database are potentially impacted by 
these vulnerabilities.


CVE-ID: CVE-2014-6567

CVSS Base Score: 9.000

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100065 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C)

DESCRIPTION

Unspecified vulnerability in the Core RDBMS component in Oracle Database 
Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote 
authenticated users to affect confidentiality, integrity, and availability via
unknown vectors.


CVE-ID: CVE-2014-6577

CVSS Base Score: 6.8

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100066 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N)

DESCRIPTION

Unspecified vulnerability in the XML Developer's Kit for C component in Oracle
Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote 
authenticated users to affect confidentiality via unknown vectors.


CVE-ID: CVE-2015-0373

CVSS Base Score: 6.5

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100067 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P)

DESCRIPTION

Unspecified vulnerability in the OJVM component in Oracle Database Server 
11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote 
authenticated users to affect confidentiality, integrity, and availability via
unknown vectors.


CVE-ID: CVE-2014-6578

CVSS Base Score: 6.5

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100068 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P)

DESCRIPTION

Unspecified vulnerability in the Workspace Manager component in Oracle 
Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote 
authenticated users to affect confidentiality, integrity, and availability via
vectors related to SDO_TOPO and WMSYS.LT.


CVE-ID: CVE-2014-6541

CVSS Base Score: 6.3

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100069 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:M/Au:S/C:C/I:N/A:N)

DESCRIPTION

Unspecified vulnerability in the Recovery component in Oracle Database Server
11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows,
allows remote authenticated users to affect confidentiality via vectors 
related to DBMS_IR.


CVE-ID: CVE-2015-0371

CVSS Base Score: 4.9

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100070 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:P)

DESCRIPTION

Unspecified vulnerability in the Core RDBMS component in Oracle Database 
Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated
users to affect integrity and availability via unknown vectors.


CVE-ID: CVE-2014-6514

CVSS Base Score: 4.0

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100071 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N)

DESCRIPTION

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 
11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users 
to affect confidentiality via unknown vectors.


CVE-ID: CVE-2015-0370

CVSS Base Score: 3.5

CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100072 for more 
information

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

DESCRIPTION

Unspecified vulnerability in the Core RDBMS component in Oracle Database 
Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated
users to affect integrity via unknown vectors.

Affected Products and Versions

IBM OpenPages with Database 6.2 through 7.0

Remediation/Fixes

A fix has been created for each affected version of the named product. 
Download and install the appropriate fix as soon as practicable. Fixes and 
installation instructions are provided at the URLs listed below:

Patch 					Download URL

IBM OpenPages with Database IF 4 	http://www.ibm.com/support/docview.wss?uid=swg24039907

Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product support 
alerts like this.

References

Complete CVSS Guide

On-line Calculator V2

Related information

IBM Secure Engineering Web Portal

IBM Product Security Incident Response Blog

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the 
Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVUBkUBLndAQH1ShLAQKvNg/+PDK29l4LavA6apdHEgEIG+otuhLiijx9
AZxHT9L6DLCNLjWLMU79p34Wxx/84KQJTenMXDICyrILBVK5sw5Dhy9qGEWXyATo
0q7BBMCJoFnTIj8u+0D/7pfCYR0KAjNpa40INwvAthvdZX3lW0etuWvTuDPBr0w2
pmGUwTsdKlZngeGp+RWREvzI1cmdDvonf9yQWmVMX6vpVIJnK9pDOzSdD8Ebu44R
Ss2akylRJi8zZTkbGjLS4Fue3NDw6RfsbSYX6gwkVmNX+acuoor+7S/iqTKbg6R3
PUKHVw+RaV17gLABulinhrqU8Zz4kJ7mXkOxY6XzqRFpmMt6a7pKuh3DZsghb2D8
5p+C8mU4bgcnHYPbqGl4EENyxp3tlqJrxBL23fpEOOpxL6Js6XNyuxZodlNPatix
ggliy6QfPDrBxTzg5HfBHfGnJL4+a3o/PWCqnXopBELYoD2surCP/Dy0mYQcfc6M
eQMsm3FiFyXH0ZhYuWtDcCwmgC7w1UMIQuK4K0ITg56E3KJx/NSpdosoG3KzEtW4
OWR/X1CtuqtxO6krLPuswUyWBZCnAADPnH82Xcy5xhT2pU0xEKD0Yo05R7gkI/qE
TKXjwXoaCsgP9ory8LQzdHtt0R2SMTVEeXdBggXJ4gkVnl2s9FmGURkvXbQVhjKw
/3DTMLbme+Q=
=HAfi
-----END PGP SIGNATURE-----