
====================================================================

                           CERT-Renater

               Note d'Information No. 2015/VULN099
_____________________________________________________________________

DATE                : 26/05/2015

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running IBM Tivoli Security Policy Manager
                            versions 7.0, 7.1.

======================================================================
http://www-01.ibm.com/support/docview.wss?uid=swg21903252
______________________________________________________________________

Security Bulletin: A security vulnerability has been identified in IBM
WebSphere Application Server shipped with IBM Tivoli Security Policy
Manager (CVE-2015-1920)

Security Bulletin

Document information

More support for:

Tivoli Security Policy Manager

Software version:

7.0, 7.1

Operating system(s):

AIX, Linux xSeries, Linux zSeries, Solaris, Windows

Reference #:

1903252

Modified date:

2015-05-21


Summary

IBM WebSphere Application Server is shipped as a component of IBM
Tivoli Security Policy Manager (TSPM). Information about a security
vulnerability affecting IBM WebSphere Application Server has been
published in a security bulletin.


Vulnerability Details

Please consult the security bulletin Security Vulnerability in IBM
WebSphere Application Server (CVE-2015-1920) for vulnerability details
and information about fixes.


Affected Products and Versions

Product Version                          WebSphere version
IBM Tivoli Security Policy Manager 7.1 WebSphere Application Server 6.1
                                       WebSphere Application Server 7.0
                                       WebSphere Application Server 8.0
IBM Tivoli Security Policy Manager 7.0 WebSphere Application Server 6.1
                                       WebSphere Application Server 7.0


Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product
support alerts like this.

References

Complete CVSS Guide
On-line Calculator V2

Related information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
Security Vulnerability in IBM WebSphere Application Server (CVE-2015-1920)

Change History

May 21, 2015 Original Version Published

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the
impact of this vulnerability in their environments by accessing the
links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST),
the Common Vulnerability Scoring System (CVSS) is an "industry open
standard designed to convey vulnerability severity and help to determine
urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS"
WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE
RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY
VULNERABILITY.

==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================
