-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2016.1332
  Security Bulletin: Vulnerability in InstallAnywhere affects IBM Content
    Collector for SAP Applications on Microsoft Windows (CVE-2016-4560)
                                26 May 2016

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Content Collector for SAP Applications
Publisher:         IBM
Operating System:  Windows
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2016-4560  

Reference:         ESB-2016.1299
                   ESB-2016.1265

Original Bulletin: 
   http://www.ibm.com/support/docview.wss?uid=swg21982743

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: Vulnerability in InstallAnywhere affects IBM Content
Collector for SAP Applications on Microsoft Windows (CVE-2016-4560)

Security Bulletin

Document information

More support for:

Content Collector for SAP Applications

Software version:

2.2.0, 3.0.0, 3.0.0.1, 3.0.0.2

Operating system(s):

Windows

Reference #:

1982743

Modified date:

2016-05-25

Summary

IBM Content Collector for SAP Applications on Microsoft Windows is affected
by a vulnerability caused by InstallAnywhere.

Vulnerability Details

CVEID:

CVE-2016-4560

DESCRIPTION:

Flexera InstallAnywhere could allow a local attacker to gain elevated
privileges on the system, caused by an untrusted search path. An attacker
could exploit this vulnerability using a Trojan horse DLL in the current
working directory of a setup-launcher executable file to gain elevated
privileges on the system.

CVSS Base Score: 7.8

CVSS Temporal Score: See

https://exchange.xforce.ibmcloud.com/vulnerabilities/113016

for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

IBM Content Collector for SAP Applications V2.2

IBM Content Collector for SAP Applications V3.0

Remediation/Fixes

For IBM Content Collector for SAP Applications V2.2

IBM recommends upgrading to a fixed, supported version of the product.

IBM Content Collector for SAP Applications V4.0 is immune against this
vulnerability, since it uses IBM Installation Manager instead of Flexera
InstallAnywhere.

Workarounds and Mitigations

To install:

1. As an administrator, create a new secure directory. The directory must not
exist before and only the administrator should have write permission to it.

2. Unzip or copy the files from your installation media into this new 
directory.

3. Rename the file install.exe to ICCSAP_install.exe. Do not skip this step.

4. in install.bat change the line

set exe_path=install.exe

to

set exe_path=ICCSAP_install.exe

5. Ensure there are no DLL files in this directory.

6. Run install.bat from this directory to install the product. Proceed with 
the installation as normal.

Get Notified about Future Security Bulletins

Subscribe to

My Notifications

to be notified of important product support alerts like this.

References

Complete CVSS v3 Guide
On-line Calculator v3

Related information

IBM Secure Engineering Web Portal

IBM Product Security Incident Response Blog

Change History

26 May 2016 - Original version

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the impact
of this vulnerability in their environments by accessing the links in the
Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the
Common Vulnerability Scoring System (CVSS) is an "industry open standard
designed to convey vulnerability severity and help to determine urgency and
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBV0Z5G36ZAP0PgtI9AQJa2A/+Opxu06O4UvVH1SDOxonZeeix8petBqaO
dOsvwZzx+h2Z4Q5S20K2T1VHOB0stb/IgGY9937JB8YHRnKRjFx+qFNnUni4V5hy
6v2LnxQcAMK5mMUKy9LUDtxkOZkPVsdbwLykmpiK/Ih10hFbgwk17IPG7QmHI32a
IEJm9eYbz9kNEFTqsH9JIy3pHLsZb3ctBIAbH9T0m/V3vSk+nf/dLxJ4+oqaTLtf
igqT5t90ZG9cvHbLkgYFbAefRXSAT5vUrdzuErqj1GJ8R1LSNx6SLFJkHVwy1IHA
BHZzX680YB6qUvis05aBTbKzBGTtN2tSCcpaGfA21tPwGEO7dezYWB1rzE8A3UQC
r0tYNh/6SDoMDGueiSU4nmI6qUEm6oTcPTwykPFWDdESO57OiRBKUjDPSxu9V1al
83lujAw/z2+862ubgY/RrjeLd917Opqvyo0M22ZnZOfLRAVsBgvgSRo4b91VY0DS
Hu0BmPN9aozyq0EpyuwxcPAAp1mCM+WTXvMbg5/qtaYz8Mui1X6LsPtRpJQ3ognx
H4G7vbZznoI8gfUA1TJlU6eV89Lq8veU4O7m5J/OByFPGLEM5vT4VHjDHdYr/D85
IlGYhzc3SjzLuQ+S88nillGDkDfERE/sE2yWL/+YVqMabZrKQ46mkfe6La11OqDK
VTISmEF0SfE=
=g3II
-----END PGP SIGNATURE-----