Skip to content

Summary

There is a potential remote code execution vulnerability in WebSphere Application Server.

Vulnerability Details

CVEID: CVE-2018-1567
DESCRIPTION: IBM WebSphere Application Server could allow remote attackers to execute arbitrary Java code through the SOAP connector with a serialized object from untrusted sources.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/143024 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

This vulnerability affects the following versions and releases of IBM WebSphere Application Server:

  • Version 9.0
  • Version 8.5
  • Version 8.0
  • Version 7.0

Remediation/Fixes

This set of fixes for PH03986 are replacements for those originally provided for APAR PI95973.  If you have PI95973 installed, you must install this new interim fix.  PH03986 includes the vulnerability fix from PI95973 and an additional fix for a problem it causes in some environments.   There is no need to uninstall the fix for PI95973 before installing the fix for PH03986.

With this iFix applied, during server shutdown, you may see an FFDC for an java.lang.reflect.UndeclaredThrowableException error in the application server log.  This FFDC is not an artifact of the original security vulnerability and can be ignored at this time.

The recommended solution is to apply the interim fix, Fix Pack or PTF containing APAR PH03986 for each named product as soon as practical.

For WebSphere Application Server traditional and WebSphere Application Server Hypervisor Edition:

For V9.0.0.0 through 9.0.0.9:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH03986
–OR–
· Apply Fix Pack 9.0.0.10 or later (targeted availability 4Q2018)

For V8.5.0.0 through 8.5.5.14:
· Upgrade to minimal fix pack levels as required by interim fix and then apply Interim Fix PH03986
–OR–
· Apply Fix Pack 8.5.5.15 or later  (targeted availability 1Q2019)

For V8.0.0.0 through 8.0.0.15:
· Upgrade to fix pack level 8.0.0.15 and then apply Interim Fix PH03986

For V7.0.0.0 through 7.0.0.45:
· Upgrade to fix pack level 7.0.0.45 and then apply Interim Fix PH03986

WebSphere Application Server V7 and V8 are no longer in full support; IBM recommends upgrading to a fixed, supported version/release/platform of the product.

Back To Top