Propust u radu paketa IBM Tivoli Common Reporting može dovesti do izvođenja napada uskraćivanja usluga.
Paket: | IBM Tivoli Common Reporting 1.x |
Operacijski sustavi: | HP-UX 11.x, IBM AIX 5.x, IBM AIX 6.x, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Red Hat Enterprise Linux 5, Sun Solaris 9, Sun Solaris 10, SUSE Linux Enterprise Server (SLES) 11 |
Kritičnost: | 3.4 |
Problem: | pogreška u programskoj komponenti |
Iskorištavanje: | lokalno/udaljeno |
Posljedica: | uskraćivanje usluga (DoS) |
Rješenje: | programska zakrpa proizvođača |
CVE: | CVE-2010-4476 |
Izvorni ID preporuke: | ADV-CIS-2011-07-0367 |
Izvor: | IBM |
Problem: | |
Propust se javlja zbog pogreške u metodi Double.parseDouble u komponenti Java Runtime Environment (JRE). |
Posljedica: | |
Uspješnim iskorištavanjem propusta može doći do izvođenja DoS napada. |
Rješenje: | |
Svim se korisnicima ranjivog paketa preporuča korištenje dostupne programske nadogradnje. |
Izvorni tekst preporuke
||Readme file for IBM Tivoli Common Reporting Interim Fix 10||
+----------------------------- NOTE --------------------------------+
|Before using this information and the product it supports, read the|
|information in 4."Notices". |
This edition applies to Interim Fix 10 for version 1, release 2, Fix Pack 1 of IBM Tivoli Common Reporting (program number 5724-T69).
Copyright International Business Machines Corporation 2010.
US Government Users Restricted Rights -- Use, duplication or disclosure
restricted by GSA ADP Schedule Contract with IBM Corp.
|Table of Contents|
1. Description
1.1 APARs included
1.2 Internal defects
2. Applying Tivoli Common Reporting Interim Fix 10
3. Uninstalling Tivoli Common Reporting Interim Fix 10
4. Notices
| 1. Description|
The Interim Fix 10 for Tivoli Common Reporting contains fix for the Java Vulnerability issue - Denial of Service.
More about this issue can be found at
This readme contains the most current information for this interim fix and takes precedence over all other documentation.
| 1.1 APARs included|
The Interim Fix 10 for Tivoli Common Reporting contains fixes for the following APARs:
PM32184 - Ship SDK IFIX to address SECURITY VULNERABILITY - WSAS V6.1.0.33
Ship SDK iFix to address a security vulnerability that causes an infinite loop in the application.
This fix will add the security patch to the TIP's JRE.
Note: This fix supports only 32-bit installation.
| 1.2 Internal defects|
| 2 Applying Tivoli Common Reporting Interim Fix 10|
To apply the fix:
1. On the computer where Tivoli Common Reporting server has been
installed, unpack the into a temporary
2. Stop the Tivoli Common Reporting server.
3. Set the enviromnet variable WASUI_HOME to the Websphere UpdateInstaller Home.
- Windows Platform
set WASUI_HOME=<Install_Location_WASUI>
For eg, WASUI_HOME=C:\IBM\UpdateInstaller
- Linux and Unix Platforms
export WASUI_HOME=<Install_Location_WASUI>
For eg, export WASUI_HOME=/opt/IBM/UpdateInstallaer
If the user is non-root users, make sure the user has the write permission for the
WebSphere UpdateInstaller directory.
4. Install the interim fix by running the following command from shell:
install[.sh|.bat] -i <TCR_1201_HOME>,
- where <TCR_1201_HOME> is the directory where Tivoli Common Reporting
is installed.
- You may have to add executable permission (+x) for the
script on Linux/UNIX platforms (chmod u+x
- Due to case-sensitivity of Deployment Engine, the value used for
<TCR_1201_HOME> must be exactly the same as the directory path
entered during the TCR installation. A common error is to
use a non capital letter for the installation drive on Windows.
If the disk where you installed Tivoli Common Reporting server
is "C:", you have to use a capital letter when specifying it,
for example:
install.bat -i c:\IBM\tivoli\tip will not work, while
install.bat -i C:\IBM\tivoli\tip will work.
5. Verify the installation:
Navigate to the folder where the Deployment Engine
has been installed.
For Windows the folder is:
C:\Program Files\IBM\Common\acsi\bin or
C:\Program Files (x86)\IBM\Common\acsi\bin (for 64bit systems)
Type listUI.cmd and the output should show that the TCR Interim
Fix 10 has been installed.
For UNIX-like systems:
Source the DE environment by running the following command:
. /var/ibm/common/acsi/ for root user, or
. ~/.acsi_<USERNAME>/ for non-root users.
Make sure you include the . (dot and space) characters when
running the command.
Browse to the following directory:
/usr/ibm/common/acsi/bin for root user, or
~/.acsi_<USERNAME>/bin for non-user users.
Type and the output should show that the TCR Interim
Fix 10 has been installed.
6. Start the Tivoli Common Rerporting server.
| 3 Uninstalling Tivoli Common Reporting Interim Fix 10|
To remove from your Tivoli Common Reporting instance the Tivoli Common Reporting Interim Fix 10, follow these steps:
1. Stop the Tivoli Common Reporting server.
2. Run the following command from shell:
install[.sh|.bat] -r <TCR_1201_HOME>
3. Start the server.
Posljednje sigurnosne preporuke