Security Bulletin
Summary
There are multiple vulnerabilities in IBM SDK for Java Technology Edition that is used by IBM Business Process Manager and WebSphere Lombardi Edition. This also includes a fix for the Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). These issues were disclosed as part of the IBM Java SDK updates in October 2014.
Vulnerability Details
CVEID: CVE-2014-6512
DESCRIPTION: An unspecified vulnerability related to the Libraries component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97147 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVEID: CVE-2014-6457
DESCRIPTION: An unspecified vulnerability related to the JSSE component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97148 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N)
CVEID: CVE-2014-6558
DESCRIPTION: An unspecified vulnerability related to the Security component has no confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97151 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N)
CVEID: CVE-2014-3566
DESCRIPTION: Product could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and access the plaintext of encrypted connections. The IBM SDK for Java Technology Edition has changed the default to eliminate the POODLE vulnerability. There is a new system property com.ibm.jsse2.disableSSLv3 It is defaulted to true so that it will not use SSLv3. If you want to take the risk you may turn SSLv3 back on with the system property: com.ibm.jsse2.disableSSLv3=false
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97013 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
For more information on CVE-2014-3566, please refer to the links in the reference section.
IBM recommends that you review your entire environment to identify areas that enable the SSLv3 protocol and take appropriate mitigation and remediation actions. The most immediate mitigation action that can be taken is disabling SSLv3. You should verify disabling SSLv3 does not cause any compatibility issues.
Affected Products and Versions
- IBM Business Process Manager Standard 7.5.x, 8.0.x, and 8.5.x
- IBM Business Process Manager Express 7.5.x, 8.0.x, and 8.5.x
- IBM Business Process Manager Advanced 7.5.x, 8.0.x, and 8.5.x
- WebSphere Lombardi Edition 7.2.x
If you are using an earlier unsupport version, IBM strongly recommends to upgrade.
Remediation/Fixes
Install WebSphere Application Server interim fixes as appropriate for your current IBM Business Process Manager or WebSphere Lombardi Edition version as described in the Security Bulletin: Multiple vulnerabilities in IBM SDK for Java Technology Edition affect WebSphere Application Server October 2014 CPU document.
Be aware that the CVE-2014-3566 (POODLE) requires an additional fix for Process Designer (IT05359) and (BPM-only) Business Space (JR51686) as described in Security Bulletin: Vulnerability in SSLv3 affects IBM Business Process Manager (CVE-2014-3566)
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
Important Note
IBM strongly suggests that all System z customers be subscribed to the System z Security Portal to receive the latest critical System z security and integrity service. If you are not subscribed, see the instructions on the System z Security web site. Security and integrity APARs and associated fixes will be posted to this portal. IBM suggests reviewing the CVSS scores and applying all security or integrity fixes as soon as possible to minimize any potential risk.
References
Security Bulletin: Multiple vulnerabilities in IBM SDK for Java Technology Edition affect WebSphere Application Server October 2014 CPU
Security Bulletin: Vulnerability in SSLv3 affects IBM Business Process Manager (CVE-2014-3566)
Security Bulletin: Vulnerability in SSLv3 affects WebSphere Lombardi Edition (CVE-2014-3566)
Change History
2014-12-18 - inital version published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Product Synonym
WLE;BPM
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg21692787