[closed] Security Vulnerablility NOT resolved by CLM 4.0.6??
Hi all,
I was emailed about a Security Bulletin today:
http://www-01.ibm.com/support/docview.wss?uid=swg21664566
If you follow the various links in the Remediation/Fixes section you eventually get to this page:
How to block the Install URL from being accessed with CLM
I tested our 4.0.5 server using the Verification Testing section of this second page and confirmed that we weren't getting the 403 error.
I decided I'd best kick off the upgrade to 4.0.6 process a.s.a.p.
I upgraded our test server from 4.0.5 to 4.0.6 and noticed that when I performed the Verification Testing again on the upgraded 4.0.6 server I still wasn't getting the 403 error as expected.
Does this mean that in fact the vulnerability exists in 4.0.6 as well?
Can anyone else with a 4.0.6 confirm that this is the case for them?
I performed the steps in the second page for updating the web.xml files on the upgraded 4.0.6 server and I now get the expected 403 error. I'm just not sure whether that's necessary. Perhaps the web.xml files update is a quick fix and the real fix is already protecting the server?
Many Thanks,
Robin
I was emailed about a Security Bulletin today:
http://www-01.ibm.com/support/docview.wss?uid=swg21664566
If you follow the various links in the Remediation/Fixes section you eventually get to this page:
How to block the Install URL from being accessed with CLM
I tested our 4.0.5 server using the Verification Testing section of this second page and confirmed that we weren't getting the 403 error.
I decided I'd best kick off the upgrade to 4.0.6 process a.s.a.p.
I upgraded our test server from 4.0.5 to 4.0.6 and noticed that when I performed the Verification Testing again on the upgraded 4.0.6 server I still wasn't getting the 403 error as expected.
Does this mean that in fact the vulnerability exists in 4.0.6 as well?
Can anyone else with a 4.0.6 confirm that this is the case for them?
I performed the steps in the second page for updating the web.xml files on the upgraded 4.0.6 server and I now get the expected 403 error. I'm just not sure whether that's necessary. Perhaps the web.xml files update is a quick fix and the real fix is already protecting the server?
Many Thanks,
Robin
The question has been closed for the following reason: "Current product version is no longer supported." by krzysztofkazmierczyk Jan 03 '20, 4:00 a.m.
Accepted answer
Robin, my understanding was that the code in the 4.0.6 is fixed to remove the vulnerability. The modification in the web.xml is only a "hot fix" needed to protect other versions of the tool that have the vulnerability and that can not immediately be upgraded to a fixed version. It removes the ability to get to the pages that expose the vulnerability.
So the modification in the web.xml is not required in 4.0.6 as far as I understand it.
So the modification in the web.xml is not required in 4.0.6 as far as I understand it.
Comments
2 votes
2 votes