Kort vurdering:
Kritisk: Moderat kritisk
Betydning: Sikkerhedsomgåelse
Hvor: Fra Lokalt Netværk
SA ID: SA17484
Berørt software:
AIX 5.x
IBM Tivoli Access Manager for Business Integration 5.x
IBM Tivoli Access Manager for e-business 5.x
IBM Tivoli Access Manager for Operating Systems 5.x
IBM Tivoli Directory Integrator 5.x
IBM Tivoli Directory Integrator 6.x
IBM Tivoli Directory Server 5.x
IBM Tivoli Directory Server 6.x
IBM Tivoli Federated Identity Manager 6.x
IBM Tivoli Identity Manager 4.x
IBM Tivoli Intelligent Orchestrator 3.x
IBM Tivoli Provisioning Manager 2.x
IBM Tivoli Provisioning Manager 3.x
IBM WebSphere Business Integration for Healthcare Collaborative Network 1.x
IBM WebSphere Portal for Multiplatforms 4.x
IBM WebSphere Portal for Multiplatforms 5.x
Beskrivelse:
Der er rapporteret en sårbarhed i IBM Tivoli Directory Server (ITDS), som kan udnyttes af ondsindede personer til at omgå visse sikkerhedsrestriktioner.
Sårbarheden skyldes en uspecificeret fejl og kan udnyttes til at ændre, modificere og / eller slette data gemt i IBM Tivoli Directory Serveren.
Sårbarheden er rapporteret i version 5.2.0 og 6.0.0.
ITDS er inkluderet i følgende produkter:
* Tivoli Identity Manager version 4.6 (ITDS version 6.0.0).
* Tivoli Access Manager for Business Integration (AMBI) version 5.1 (ITDS version 5.2.0).
* Tivoli Access Manager for e-business (TAM) version 5.1 (ITDS version 5.2.0).
* Tivoli Access Manager for Operating Systems (TAMOS) version 5.1 (ITDS version 5.2.0).
* Tivoli Directory Integrator (ITDI) version 5.2 and version 6.0 (ITDS version 5.2.0).
* Tivoli Federated Identity Manager version 6.0 (ITDS version 5.2.0).
* Tivoli Intelligent ThinkDynamic Orchestrator, version 2.1.0 (ITDS version 5.2.0).
* Tivoli Intelligent Orchestrator, version 3.1.0 (ITDS version 5.2.0).
* Tivoli Provisioning Manager, version 2.1.0 (ITDS version 5.2.0).
* Tivoli Provisioning Manager, version 3.1.0 (ITDS version 5.2.0).
* WebSphere Business Integration for Healthcare Collaborative Network 1.0
* WebSphere Portal for Multiplatforms version 4.1.6, 4.2, 4.2.1, and 4.2.2
* WebSphere Portal for Multiplatforms version 5.0, 5.0.2, and 5.0.2.1 to 5.0.2.3,
* WebSphere Portal for Multiplatforms version 5.1.0.1 and 5.1.0.2.
* AIX 5.2 and 5.3.
Løsning:
Installér patches.
ITDS Version 5.2.0:
Installér APAR IO02697.
ITDS Version 5.2.0.3-TIV-ITDS-IF0001 or earlier (This will update ITDS to fixpack 3):
Installér cumulative interim fix 1.
http://www-1.ibm.com/support/docview.wss?uid=swg24010820
ITDS Version 5.2.0.3-TIV-ITDS-IF0007:
Installér cumulative interim fix 7.
http://www-1.ibm.com/support/docview.wss?uid=swg24010821
ITDS Version 5.2.0.3-TIV-ITDS-LA0011:
Kontakt IBM Tivoli Support.
ITDS Version 6.0.0:
Installér APAR IO02714.
ITDS Version 6.0.0.1-TIV-ITDS-IF0001:
Installér cumulative interim fix 1.
http://www-1.ibm.com/support/docview.wss?uid=swg24010819
AIX Version 5 APARs kan downloades fra:
http://www-1.ibm.com/servers/eserver/support/pseries/aixfixes.html
Rapporteret af / Kredit:
Rapporteret af producenten.
Forløb:
10-11-2005: Opdaterede berørte produkter. Opdaterede beskrivelse og original advisory.
15-11-2005: Opdaterede berørte produkter. Opdaterede beskrivelse og original advisory.
Relaterede Advisories: AIX "diagela" uspecificeret sårbarhed
AIX "swcons" kommando buffer overflow
IBM "chcons" buffer overflow
AIX LSCFG usikker håndtering af midlertidige filer
AIX tcpdump BGP Denial of Service
AIX "getconf" kommando buffer overflow
AIX ftpd uspecificeret Denial of Service
AIX flere rettighedseskalerings-sårbarheder
AIX diverse kommunikations-protokoller Denial of Service
AIX uspecificeret NIS-klient systemkompromittering
