-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2014.0262
    Security Bulletin: IBM Content Navigator - Multiple vulnerabilities
                             28 February 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Content Navigator
Publisher:         IBM
Operating System:  AIX
                   Linux variants
                   Windows
Impact/Access:     Denial of Service    -- Remote/Unauthenticated      
                   Cross-site Scripting -- Remote with User Interaction
                   Unauthorised Access  -- Existing Account            
Resolution:        Patch/Upgrade
CVE Names:         CVE-2014-0874 CVE-2014-0858 CVE-2013-5879
                   CVE-2013-5442  

Reference:         ASB-2014.0005
                   ESB-2014.0069
                   ESB-2013.1604

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=swg21665358
   http://www-01.ibm.com/support/docview.wss?uid=swg21665360
   http://www-01.ibm.com/support/docview.wss?uid=swg21665361
   http://www-01.ibm.com/support/docview.wss?uid=swg21665362

Comment: This bulletin contains four (4) IBM security advisories.

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: Improper authorization by non-admin user in IBM Content 
Navigator (CVE-2014-0858)

Document information

More support for:
Content Navigator

Software version:
2.0, 2.0.1, 2.0.2

Operating system(s):
AIX, Linux, Linux on System z, Windows

Reference #:
1665358

Modified date:
2014-02-26

Security Bulletin

Summary

Using 3rd party tools, a non-admin user can modify the URL action so that 
instead of a getAction, the user can perform a deleteAction against the 
configuration database.

Vulnerability Details

CVEID: CVE-2014-0858
DESCRIPTION: 
Improper authorization by non-admin user

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90864 for the 
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

Affected Products

IBM Content Navigator 2.0.0, 2.0.1, and 2.0.2

IBM Content Navigator is a component that is available to customers in these 
products (and the products that contain them):
- - IBM Content Manager
- - IBM FileNet Content Manager
- - IBM Content Foundation
- - IBM Content Manager OnDemand

Remediation/Fixes

Version 2.0.0: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002

Version 2.0.1: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002

Version 2.0.2: Apply fix pack 2.0.2.2-ICN-FP002

Workarounds/Mitigations

None known, apply fixes

References:

Complete CVSS Guide 
On-line Calculator V2

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of 
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.

Note: According to the Forum of Incident Response and Security Teams (FIRST), 
the Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- ----------------------------

Security Bulletin: IBM Content Navigator – Cross-site Scripting vulnerability 
in Knowledge Center Local Edition (CVE-2013-5442)

Document information

More support for:
Content Navigator

Software version:
2.0, 2.0.1, 2.0.2

Operating system(s):
AIX, Linux, Linux on System z, Windows

Reference #:
1665360

Modified date:
2014-02-26

Security Bulletin

Summary

Cross-site Scripting vulnerability in Knowledge Center Local Edition

Vulnerability Details

CVEID: CVE-2013-5442 
The following security vulnerability exist in the Knowledge Center Local 
Edition shipped with IBM Content Navigator

CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/87818 
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Affected Products
IBM Content Navigator 2.0.0, 2.0.1, and 2.0.2

IBM Content Navigator is a component that is available to customers in these 
products (and the products that contain them):
- - IBM Content Manager
- - IBM FileNet Content Manager
- - IBM Content Foundation
- - IBM Content Manager OnDemand

Remediation/Fixes

Version 2.0.1: Upgrade to IBM Content Navigator version 2.0.2 and apply fix 
pack 2.0.2.2-ICN-FP002 

Version 2.0.2: Apply fix pack 2.0.2.2-ICN-FP002

Workarounds/Mitigations

Version 2.0.0: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002

Version 2.0.1: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002

Version 2.0.2: Apply fix pack 2.0.2.2-ICN-FP002

References:

Complete CVSS Guide 
On-line Calculator V2

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of 
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.
Note: According to the Forum of Incident Response and Security Teams (FIRST), 
the Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- ------------------------------------

Security Bulletin: Open Source Oracle Jan 2014 - Oracle Outside In 
vulnerability in IBM Content Navigator (CVE-2013-5879)

Document information

More support for:
Content Navigator

Software version:
2.0.1, 2.0.2

Operating system(s):
AIX, Linux, Linux on System z, Windows

Reference #:
1665361

Modified date:
2014-02-26

Security Bulletin

Summary

Open Source Oracle Jan 2014 - Oracle Outside In vulnerability

Vulnerability Details

CVEID: CVE-2013-5879
DESCRIPTION: 
An unspecified vulnerability in Oracle Outside In Technology related to the 
Outside In Maintenance component could allow a local attacker to cause a 
denial of service.

CVSS Base Score: 1.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90282 for the 
current score 
CVSS Environmental Score*: Undefined 
CVSS Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:P)
Affected Products
IBM Content Navigator 2.0.1, and 2.0.2

IBM Content Navigator is a component that is available to customers in these 
products (and the products that contain them):
- - IBM Content Manager
- - IBM FileNet Content Manager
- - IBM Content Foundation
- - IBM Content Manager OnDemand

Remediation/Fixes

Version 2.0.1: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002 

Version 2.0.2: Apply fix pack 2.0.2.2-ICN-FP002

References:

Complete CVSS Guide 
On-line Calculator V2

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of 
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.
Note: According to the Forum of Incident Response and Security Teams (FIRST),
the Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------

Security Bulletin: Reflected Cross-Site Scripting Vulnerability in IBM Content 
Navigator (CVE-2014-0874)

Document information

More support for:
Content Navigator

Software version:
2.0, 2.0.1, 2.0.2

Operating system(s):
AIX, Linux, Linux on System z, Windows

Reference #:
1665362

Modified date:
2014-02-26

Security Bulletin

Summary

Reflected Cross-Site Scripting Vulnerability in IBM Content Navigator

Vulnerability Details

CVEID: CVE-2014-0874
DESCRIPTION: 
Arbitrary characters inserted into request parameters are not properly encoded. 
Not encoding user-supplied input may expose a web application to cross-site 
scripting.

CVSS Base Score: 3.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/91002 for the 
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)
Affected Products
IBM Content Navigator 2.0.0, 2.0.1, and 2.0.2

IBM Content Navigator is a component that is available to customers in these 
products (and the products that contain them):
- - IBM Content Manager
- - IBM FileNet Content Manager
- - IBM Content Foundation
- - IBM Content Manager OnDemand

Remediation/Fixes

Version 2.0.0: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002 
Version 2.0.1: Upgrade to Content Navigator 2.0.2 and apply fix pack 
2.0.2.2-ICN-FP002

Version 2.0.2: Apply fix pack 2.0.2.2-ICN-FP002

Workarounds/Mitigations

None known, apply fixes

References:

Complete CVSS Guide 
On-line Calculator V2

*The CVSS Environment Score is customer environment specific and will 
ultimately impact the Overall CVSS Score. Customers can evaluate the impact of 
this vulnerability in their environments by accessing the links in the 
Reference section of this Security Bulletin.

Note: According to the Forum of Incident Response and Security Teams (FIRST), 
the Common Vulnerability Scoring System (CVSS) is an "industry open standard 
designed to convey vulnerability severity and help to determine urgency and 
priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY 
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS 
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT 
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUw/kVRLndAQH1ShLAQJq9A//aSkgcv/x3s4UsfxiGuyRT/8OCDSJQqAG
lq0uv9sog08AA9Sq7ecLO1s6RuBHGiHdH5q8IF1GHNmhuouiRTJwD3lljuLwm0iv
Sf5FPnIPziWzaDb9jvlSeHZzD4u1sDFn1goOhauj2J1jZBe9LiVjIH5JL0DV+y1t
kMzLLfgfTvKrrcPj4dx+CtsP6I2m3qEyrzhzg1VtZFX0G1ASqqPJBkJfqb2DZWN+
jE2jT/odG6OMfyB2HhKLcQ8Emp/PEPZUeLZVhIFd2uFgEkLa4iDSrNEwDGiyXYCg
jwlzwx34VShKhGvN1Fvx37D4gVB+xdv+zdPJgY2uxoYjkGi1bNdcYmXOnhP8A/W5
WiqWcBV60rR7hem6JFYnvcYoy8/j3K0IoZhcVmEJPZOJv0C8zD4nIIQ1VNKya83e
XqREHbqdd/HspGl4JCTbd5hiwi6gPWjlYnIPQS1NvALFCS6CdvkzkKYLp+d9Zm/r
8I1P1un7dWWUezFpuPAO1/9DBxfr5GxDujidjM/A/B2Lf5+C5cpqn5tWcLwBrkr+
ZuKZ7sWh4rMIQAoAzjYTxxjuP2A0ZrHGdwNJszDff8w5TJiPeLL+XZz9eX/OQDYZ
UsDNqpuTJF15RPENnRFbq3ggdWhkBq9USruarwupxnyWexMiW8+3Y/BWAPIMYEmB
x5RKY+VY4/4=
=veSc
-----END PGP SIGNATURE-----