Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2015.1169 Security Bulletin: IBM OpenPages Platform with Database vulnerabilities 29 April 2015 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: IBM OpenPages with Database Publisher: IBM Operating System: AIX Windows Impact/Access: Execute Arbitrary Code/Commands -- Existing Account Modify Arbitrary Files -- Existing Account Denial of Service -- Existing Account Access Confidential Data -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2015-0373 CVE-2015-0371 CVE-2015-0370 CVE-2014-6578 CVE-2014-6577 CVE-2014-6567 CVE-2014-6541 CVE-2014-6514 Reference: ASB-2015.0009 Original Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21883820 - --------------------------BEGIN INCLUDED TEXT-------------------- Security Bulletin: IBM OpenPages Platform with Database vulnerabilities Document information More support for: OpenPages GRC Platform Software version: 6.2, 6.2.1, 7.0 Operating system(s): AIX, Windows Reference #: 1883820 Modified date: 2015-04-28 Security Bulletin Summary These security vulnerabilities exist in all versions of IBM OpenPages with Database: See Vulnerability Details for CVE IDs. Vulnerability Details Customers who have IBM OpenPages with Database are potentially impacted by these vulnerabilities. CVE-ID: CVE-2014-6567 CVSS Base Score: 9.000 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100065 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C) DESCRIPTION Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. CVE-ID: CVE-2014-6577 CVSS Base Score: 6.8 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100066 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:N/A:N) DESCRIPTION Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors. CVE-ID: CVE-2015-0373 CVSS Base Score: 6.5 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100067 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P) DESCRIPTION Unspecified vulnerability in the OJVM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. CVE-ID: CVE-2014-6578 CVSS Base Score: 6.5 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100068 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P) DESCRIPTION Unspecified vulnerability in the Workspace Manager component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SDO_TOPO and WMSYS.LT. CVE-ID: CVE-2014-6541 CVSS Base Score: 6.3 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100069 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:M/Au:S/C:C/I:N/A:N) DESCRIPTION Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality via vectors related to DBMS_IR. CVE-ID: CVE-2015-0371 CVSS Base Score: 4.9 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100070 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:P) DESCRIPTION Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity and availability via unknown vectors. CVE-ID: CVE-2014-6514 CVSS Base Score: 4.0 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100071 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N) DESCRIPTION Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors. CVE-ID: CVE-2015-0370 CVSS Base Score: 3.5 CVSS Temporal Score: http://xforce.iss.net/xforce/xfdb/100072 for more information CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N) DESCRIPTION Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity via unknown vectors. Affected Products and Versions IBM OpenPages with Database 6.2 through 7.0 Remediation/Fixes A fix has been created for each affected version of the named product. Download and install the appropriate fix as soon as practicable. Fixes and installation instructions are provided at the URLs listed below: Patch Download URL IBM OpenPages with Database IF 4 http://www.ibm.com/support/docview.wss?uid=swg24039907 Get Notified about Future Security Bulletins Subscribe to My Notifications to be notified of important product support alerts like this. References Complete CVSS Guide On-line Calculator V2 Related information IBM Secure Engineering Web Portal IBM Product Security Incident Response Blog *The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin. Disclaimer According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBVUBkUBLndAQH1ShLAQKvNg/+PDK29l4LavA6apdHEgEIG+otuhLiijx9 AZxHT9L6DLCNLjWLMU79p34Wxx/84KQJTenMXDICyrILBVK5sw5Dhy9qGEWXyATo 0q7BBMCJoFnTIj8u+0D/7pfCYR0KAjNpa40INwvAthvdZX3lW0etuWvTuDPBr0w2 pmGUwTsdKlZngeGp+RWREvzI1cmdDvonf9yQWmVMX6vpVIJnK9pDOzSdD8Ebu44R Ss2akylRJi8zZTkbGjLS4Fue3NDw6RfsbSYX6gwkVmNX+acuoor+7S/iqTKbg6R3 PUKHVw+RaV17gLABulinhrqU8Zz4kJ7mXkOxY6XzqRFpmMt6a7pKuh3DZsghb2D8 5p+C8mU4bgcnHYPbqGl4EENyxp3tlqJrxBL23fpEOOpxL6Js6XNyuxZodlNPatix ggliy6QfPDrBxTzg5HfBHfGnJL4+a3o/PWCqnXopBELYoD2surCP/Dy0mYQcfc6M eQMsm3FiFyXH0ZhYuWtDcCwmgC7w1UMIQuK4K0ITg56E3KJx/NSpdosoG3KzEtW4 OWR/X1CtuqtxO6krLPuswUyWBZCnAADPnH82Xcy5xhT2pU0xEKD0Yo05R7gkI/qE TKXjwXoaCsgP9ory8LQzdHtt0R2SMTVEeXdBggXJ4gkVnl2s9FmGURkvXbQVhjKw /3DTMLbme+Q= =HAfi -----END PGP SIGNATURE-----