-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.2892
 Multiple vulnerabilities in IBM Java Runtime affect IBM Spectrum Protect
Snapshot on AIX and Linux (CVE-2018-1890, CVE-2018-12547) Security Bulletin
                               2 August 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Spectrum Protect Snapshot
                   IBM Spectrum Protect for Enterprise Resource Planning
Publisher:         IBM
Operating System:  AIX
                   HP-UX
                   Linux variants
                   Solaris
                   Windows
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Increased Privileges            -- Existing Account      
                   Denial of Service               -- Remote/Unauthenticated
                   Access Confidential Data        -- Existing Account      
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-12547 CVE-2018-1987 CVE-2018-1890

Original Bulletin: 
   http://www.ibm.com/support/docview.wss?uid=ibm10885230
   http://www.ibm.com/support/docview.wss?uid=ibm10883888
   http://www.ibm.com/support/docview.wss?uid=ibm10883782

Comment: This bulletin contains three (3) IBM security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

Multiple vulnerabilities in IBM Java Runtime affect IBM Spectrum Protect
Snapshot on AIX and Linux (CVE-2018-1890, CVE-2018-12547)

Product:             IBM Spectrum Protect Snapshot
Component:           FlashCopy Manager for Unix and Linux
Software version:    4.1, 8.1
Operating system(s): AIX, Linux
Reference #:         0885230

Security Bulletin

Summary

Multiple vulnerabilities in IBM Runtlime Environment Java were disclosed as part
of the IBM Java SDK updates in January 2019. IBM Runtime Environment Java is
used by IBM Spectrum Protect Snapshot (formerly Tivoli Storage FlashCopy
Manager) on AIX and Linux.

Vulnerability Details

CVEID: CVE-2018-1890
DESCRIPTION: IBM SDK, Java Technology Edition Version 8 on the AIX platform
uses absolute RPATHs which may facilitate code injection and privilege
elevation by local users.
CVSS Base Score: 5.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
152081 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)

CVEID: CVE-2018-12547
DESCRIPTION: Eclipse OpenJ9 is vulnerable to a buffer overflow, caused by
improper bounds checking by the jio_snprintf() and jio_vsnprintf() functions.
By sending an overly long argument, a remote attacker could overflow a buffer
and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
157512 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

The following IBM FlashCopy Manager (IBM Spectrum Protect Snapshot (fomerly
Tivoli Storage FlashCopy Manager) components on Unix and Linux are affected:

  o IBM Spectrum Protect Snapshot for DB2 versions on AIX and Linux x86 only:
    - 8.1.0.0 through 8.1.6.0
    - 4.1.0.0 through 4.1.6.2
  o IBM Spectrum Protect Snapshot for Custom Applications versions on AIX and
    Linux x86 only:
    - 8.1.0.0 through 8.1.6.0
    - 4.1.0.0 through 4.1.6.2
  o IBM Spectrum Protect Snapshot for Oracle versions on AIX and Linux x86
    only:
    - 8.1.0.0 through 8.1.6.0
    - 4.1.0.0 through 4.1.6.2
  o IBM Spectrum Protect Snapshot for Oracle with SAP environments versions on
    AIX and Linux x86 only:
    - 8.1.0.0 through 8.1.6.0
    - 4.1.0.0 through 4.1.6.2

Remediation/Fixes

+-------------------+--------+----------+-----------------------------------------------------------------+
|IBM Spectrum       |First   |          |                                                                 |
|Protect Snapshot   |Fixing  |          |                                                                 |
|for Unix and Linux |VRMF    |Platform  |                                                                 |
|Release            |Level   |          |Link to Fix                                                      |
+-------------------+--------+----------+-----------------------------------------------------------------+
|                   |        |          |https://public.dhe.ibm.com/storage/                              |
|8.1                |8.1.6.1 |AIX       |tivoli-storage-flashcopymanager/patches/v8r1/aix/v8161/          |
|                   |        |Linux     |https://public.dhe.ibm.com/storage/                              |
|                   |        |          |tivoli-storage-flashcopymanager/patches/v8r1/linux/v8161/        |
|                   |        |          |                                                                 |
|                   |        |          |                                                                 |
|                   |        |          |                                                                 |
+-------------------+--------+----------+-----------------------------------------------------------------+
|4.1                |4.1.6.3 |AIX       |https://public.dhe.ibm.com/storage/                              |
|                   |        |Linux     |tivoli-storage-flashcopymanager/patches/v4r1/aix/v4163/          |
|                   |        |          |https://public.dhe.ibm.com/storage/                              |
|                   |        |          |tivoli-storage-flashcopymanager/patches/v4r1/linux/v4163/        |
|                   |        |          |                                                                 |
+-------------------+--------+----------+-----------------------------------------------------------------+

Workarounds and Mitigations

None

Change History

31 July 2019 - original version published

- ---------------------------------------------------------------------------


Multiple vulnerabilities in IBM Java Runtime affect IBM Spectrum Protect for
Enterprise Resource Planning (CVE-2018-1890, CVE-2018-12547)

Product:             IBM Spectrum Protect for Enterprise Resource Planning
Software version:    7.1, 8.1
Operating system(s): AIX, HP-UX, Linux, Solaris, Windows
Reference #:         0883888

Security Bulletin

Summary

There are multiple vulnerabilities in IBM Runtime Environment Java which is
used by IBM Spectrum Protect (formerly Tivoli Storage Manager) for Enterprise
Resource Planning. These issues were disclosed as part of the IBM Java SDK
updates in January 2019.

Vulnerability Details

CVEID: CVE-2018-1890
DESCRIPTION: IBM SDK, Java Technology Edition Version 8 on the AIX platform
uses absolute RPATHs which may facilitate code injection and privilege
elevation by local users.
CVSS Base Score: 5.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
152081 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)

CVEID: CVE-2018-12547
DESCRIPTION: Eclipse OpenJ9 is vulnerable to a buffer overflow, caused by
improper bounds checking by the jio_snprintf() and jio_vsnprintf() functions.
By sending an overly long argument, a remote attacker could overflow a buffer
and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
157512 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

The following levels of IBM Spectrum Protect (formerly Tivoli Storage Manager)
for Enterprise Resource Planning are affected:

  o 8.1.0.0 through 8.1.6.0 - Data Protection for SAP HANA
    8.1.0.0 through 8.1.4.0 - Data Protection for SAP for Db2 and Data
    Protection for SAP for Oracle
  o 7.1.3.0 through 7.1.3.1 - Data Protection for SAP HANA, Db2, and Oracle.

Remediation/Fixes

+----------------------+---------+----------+---------------------------------------------------------------------------+
|                      |First    |          |                                                                           |
|Data Protection for   |Fixing   |Platform  |Link to Fix                                                                |
|SAP HANA Release      |VRMF     |          |                                                                           |
|                      |Level    |          |                                                                           |
+----------------------+---------+----------+---------------------------------------------------------------------------+
|8.1                   |8.1.6.1  |Linux     |https://www.ibm.com/support/docview.wssuid=ibm10879355                     |
+----------------------+---------+----------+---------------------------------------------------------------------------+
|7.1                   |7.1.3.2  |Linux     |https://www.ibm.com/support/docview.wssuid=ibm10960113                     |
+----------------------+---------+----------+---------------------------------------------------------------------------+

+---------------------+---------+----------+--------------------------------------------------------------------------+
|Data Protection for  |First    |          |                                                                          |
|SAP for Db2 and      |Fixing   |Platform  |Link to Fix                                                               |
|Oracle Release       |VRMF     |          |                                                                          |
|                     |Level    |          |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+
|8.1                  |8.1.4.1  |AIX       |https://www.ibm.com/support/docview.wssuid=ibm10888223                    |
|                     |         |Linux     |                                                                          |
|                     |         |Solaris   |                                                                          |
|                     |         |Windows   |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+
|                     |         |AIX       |https://www.ibm.com/support/docview.wssuid=ibm10960113                    |
|                     |         |HP-UX     |                                                                          |
|7.1                  |7.1.3.2  |Linux     |                                                                          |
|                     |         |Solaris   |                                                                          |
|                     |         |Windows   |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+

Workarounds and Mitigations

None

Change History

31 July 2019 - original version published

- ----------------------------------------------------------------------------


Password disclosure via application trace affects IBM Spectrum Protect for
Enterprise Resource Planning (CVE-2018-1987)

Product:             IBM Spectrum Protect for Enterprise Resource Planning
Software version:    7.1, 8.1
Operating system(s): AIX, HP-UX, Linux, Solaris, Windows
Reference #:         0883782

Security Bulletin

Summary

If tracing is activated, IBM Spectrum Protect (formerly Tivoli Storage Manager)
for Enterprise Resource Planning may display the IBM Spectrum Protect node
password in plain text in the trace file.

Vulnerability Details

CVEID: CVE-2018-1987
DESCRIPTION: IBM Tivoli Storage Manager for Enterprise Resource Planning, if
tracing is activated, the IBM Spectrum Protect node password may be displayed
in plain text in the ERP trace file.
CVSS Base Score: 5.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/
154280 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

The following levels of IBM Spectrum Protect (formerly Tivoli Storage Manager)
for Enterprise Resource Planning are affected:

  o 8.1.0.0 through 8.1.6.0 - Data Protection for SAP HANA
    8.1.0.0 through 8.1.4.0 - Data Protection for SAP for Db2 and Data
    Protection for SAP for Oracle
  o 7.1.3.0 through 7.1.3.1 - Data Protection for SAP HANA, Db2, and Oracle.

Remediation/Fixes

+----------------------+---------+----------+---------------------------------------------------------------------------+
|                      |First    |          |                                                                           |
|Data Protection for   |Fixing   |Platform  |Link to Fix                                                                |
|SAP HANA Release      |VRMF     |          |                                                                           |
|                      |Level    |          |                                                                           |
+----------------------+---------+----------+---------------------------------------------------------------------------+
|8.1                   |8.1.6.1  |Linux     |https://www.ibm.com/support/docview.wssuid=ibm10879355                     |
+----------------------+---------+----------+---------------------------------------------------------------------------+
|7.1                   |7.1.3.2  |Linux     |https://www.ibm.com/support/docview.wssuid=ibm10960113                     |
+----------------------+---------+----------+---------------------------------------------------------------------------+

+---------------------+---------+----------+--------------------------------------------------------------------------+
|Data Protection for  |First    |          |                                                                          |
|SAP for Db2 and      |Fixing   |Platform  |Link to Fix                                                               |
|Oracle Release       |VRMF     |          |                                                                          |
|                     |Level    |          |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+
|8.1                  |8.1.4.1  |AIX       |https://www.ibm.com/support/docview.wssuid=ibm10888223                    |
|                     |         |Linux     |                                                                          |
|                     |         |Solaris   |                                                                          |
|                     |         |Windows   |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+
|                     |         |AIX       |https://www.ibm.com/support/docview.wssuid=ibm10960113                    |
|                     |         |HP-UX     |                                                                          |
|7.1                  |7.1.3.2  |Linux     |                                                                          |
|                     |         |Solaris   |                                                                          |
|                     |         |Windows   |                                                                          |
+---------------------+---------+----------+--------------------------------------------------------------------------+

Workarounds and Mitigations

Tracing is disabled by default. It is normally enabled only when directed by
IBM support to troubleshoot an issue.

To minimize exposure to this vulnerability, disable tracing unless required and
delete trace files that are no longer needed.

Change History

31 July 2019 - original version published

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXUO2r2aOgq3Tt24GAQhH8g//ZSCGgrD9sflOCO3QxEgtaaoWnp0vl2Q6
mUyiDTqaIL3UQYmhySbYIuacXFx9PnfMtzU9vqJoSm0gX0+LgJQ7FRx7HzD5FicS
ZLzM8nwtNVFSpmHPV3Q6+x+morbBERkdHk6fBZ21A7G+CYvYBm346EnXXddtnD6B
/icv/ZwiCiGRiF0dQSCOoEbJiHUwSzYsm2bQsia7LkneJ8fzzshRLwc21/hCwcjZ
O3N6+hIpBtkK2muDUFm25L3k3HAFMjIf331jE2Lyq3HNa5IiNM0yV/U7FbbyW1Q7
xuodMR2HiLWxcQAJJ69UhNW9V8N58CySCbZGp2FpiE/+Q7TU7OjFtDX0yC9iS3qd
HHhfevz15KEdT2JtQfLQrR6ZEiBbWqi50iY8I6ywbT/i+fTUPXAt0tbLaDrI00VT
nTSoGKd2LPPGrkd3xA2jQLjH/Si7FDv9FsggseKhg0ijAw5O6z2gvMCjkOUJ0twF
AAm2rACTUqRjYiZTCDzA3g3hSXlo0IbIIoILBkZirtW0U0GDYZVBi1RsfwAf0RR7
eN6ojTTJVvMZLpEizfT0mn7NqX3UsQgXS0vC40px7I91pBXh9vukGkytFhPiG3iO
tM3qwG7d4OrC+S8wlIXQvsepFN8eZ+3SW6+zcj/Sq9tqrTUnz+yH9deP4jqM5llD
NRMopb0KVU4=
=RPON
-----END PGP SIGNATURE-----