Category
Security
Release Phase
Resolved
ProductSun Java System Application Server Platform Edition 8.1 2005Q1
Sun Java System Web Server 7.0
Sun Java System Web Proxy Server 4.0
Sun Java System Web Server 6.1
Sun Java System Application Server Enterprise Edition 8.1 2005Q1
Bug Id
6546271, 6534224, 6540248
Date of Workaround Release11-JUN-2007
Date of Resolved Release04-SEP-2007
Impact
Sun Java System Application Server, Web Server and Proxy Server make use of the Network Security Services (NSS) library and are impacted by a number of security vulnerabilities related to the SSL2 implementation in that library if SSL2 is enabled in these servers. These vulnerabilities may allow remote users to cause the server to exit unexpectedly, causing a denial of service (DoS) to the application, or to execute arbitrary code.
These issues are also described in the following documents:
Other Sun products make use of the NSS library. For information regarding the impact to other products, please see Sun Alert 102856 at:
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1
Contributing Factors
These issues can occur in the following releases:
SPARC Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119169-16 or (SVR4) patch 119166-24
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119173-16 or (SVR4) patch 119166-24
- Sun Java System Web Server 6.1 without Service Pack 8
- Sun Java System Web Server 6.1 without patch 116648-20
- Sun Java System Web Server 7.0 without Update 1
- Sun Java System Web Server 7.0 without patch 125437-07
- Sun Java System Web Proxy Server 4.0 without Service Pack 5
- Sun Java System Web Proxy Server 4.0 without patch 120981-12
x86 Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119170-16 or (SVR4) patch 119167-24
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119174-16 or (SVR4) patch 119167-24
- Sun Java System Web Server 6.1 without Service Pack 8
- Sun Java System Web Server 6.1 without patch 116649-20
- Sun Java System Web Server 7.0 without Update 1
- Sun Java System Web Server 7.0 without patch 125438-07
- Sun Java System Web Proxy Server 4.0 without Service Pack 5
- Sun Java System Web Proxy Server 4.0 without patch 120982-12
Linux Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119171-16 or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119175-16 or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24
- Sun Java System Web Server 6.1 without Service Pack 8
- Sun Java System Web Server 6.1 without patch 118202-12
- Sun Java System Web Server 7.0 without Update 1
- Sun Java System Web Server 7.0 without patch 125439-07
- Sun Java System Web Proxy Server 4.0 without Service Pack 5
- Sun Java System Web Proxy Server 4.0 without patch 120983-12
AIX Platform
- Sun Java System Web Server 6.1 without Service Pack 8
HP-UX Platform
- Sun Java System Web Server 6.1 without Service Pack 8
- Sun Java System Web Server 6.1 without patch 121510-04
- Sun Java System Web Server 7.0 without Update 1
- Sun Java System Web Server 7.0 without patch 125440-01
- Sun Java System Web Proxy Server 4.0 without Service Pack 5
Windows Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119172-16 or (package based patch) 122848-09
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119176-16
- Sun Java System Web Server 6.1 without Service Pack 8
- Sun Java System Web Server 6.1 without patch 121524-04
- Sun Java System Web Server 7.0 without Update 1
- Sun Java System Web Server 7.0 without patch 125441-06
- Sun Java System Web Proxy Server 4.0 without Service Pack 5
- Sun Java System Web Proxy Server 4.0.5 without patch 126325-02
To determine the version of Sun Java System Application Server on a system, the following command can be run:
$ <AS_INSTALL>/bin/asadmin version --verbose
(Where <AS_INSTALL> is the installation directory of the Application Server)
To determine the version of Sun Java System Web Server on a system, the following command can be run:
$ <WS-install>/https-<host>/start -version
(Where <WS-install> is the installation directory of the Web Server and <host> should be the actual host name on which the Web Server is installed)
To determine the version of Sun Java System Web Proxy Server on a system, the following command can be run:
$ <PS_INSTALL>/bin/ns-proxy -v
(Where <PS_INSTALL> is the installation directory of the Web Proxy Server)
Note: SSL v2 is disabled by default in the Sun Java System Application Server, Sun Java System Web Server, and Sun Java System Web Proxy Server.
Symptoms
There are no reliable symptoms that would indicate the described issues have been exploited.
Workaround
In order to work around these issues in products which use the NSS library, SSL v2 can be disabled. For example if SSL v2 has been enabled in the Sun Java System Application Server, Sun Java System Web Server, or Sun Java System Web Proxy Server then it can be disabled until patches can be applied.
The exact procedure to disable SSL v2 for each of these Sun Java System products varies. See the respective product documentation at http://docs.sun.com for further details.
Resolution
These issues are addressed in the following releases:
SPARC Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119169-16 or later or (SVR4) patch 119166-24 or later
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119173-16 or later or (SVR4) patch 119166-24 or later
- Sun Java System Web Server 6.1 with Service Pack 8 or later
- Sun Java System Web Server 6.1 with patch 116648-20 or later
- Sun Java System Web Server 7.0 with Update 1 or later
- Sun Java System Web Server 7.0 with patch 125437-07 or later
- Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
- Sun Java System Web Proxy Server 4.0 with patch 120981-12 or later
x86 Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119170-16 or later or (SVR4) patch 119167-24 or later
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119174-16 or later or (SVR4) patch 119167-24 or later
- Sun Java System Web Server 6.1 with Service Pack 8 or later
- Sun Java System Web Server 6.1 with patch 116649-20 or later
- Sun Java System Web Server 7.0 with Update 1 or later
- Sun Java System Web Server 7.0 with patch 125438-07 or later
- Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
- Sun Java System Web Proxy Server 4.0 with patch 120982-12 or later
Linux Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119171-16 or later or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24 or later
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119175-16 or later or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24 or later
- Sun Java System Web Server 6.1 with Service Pack 8 or later
- Sun Java System Web Server 6.1 with patch 118202-12 or later
- Sun Java System Web Server 7.0 with Update 1 or later
- Sun Java System Web Server 7.0 with patch 125439-07 or later
- Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
- Sun Java System Web Proxy Server 4.0 with patch 120983-12 or later
AIX Platform
- Sun Java System Web Server 6.1 with Service Pack 8 later
HP-UX Platform
- Sun Java System Web Server 6.1 with Service Pack 8 or later
- Sun Java System Web Server 6.1 with patch 121510-04 or later
- Sun Java System Web Server 7.0 with Update 1 or later
- Sun Java System Web Server 7.0 with patch 125440-01 or later
- Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
Windows Platform
- Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119172-16 or later or (package based patch) 122848-09 or later
- Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119176-16 or later
- Sun Java System Web Server 6.1 with Service Pack 8 or later
- Sun Java System Web Server 6.1 with patch 121524-04 or later
- Sun Java System Web Server 7.0 with Update 1 or later
- Sun Java System Web Server 7.0 with patch 125441-06 or later
- Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
- Sun Java System Web Proxy Server 4.0.5 with patch 126325-02 or later
Sun Java System Web Server 6.1 Service Pack 8 is available at:
Sun Java System Web Server 7.0 Update 1 is available at:
Sun Java System Web Proxy Server 4.0 Service Pack 5 is available at:
Modification History
Date: 29-AUG-2007
- Updated Contributing Factors and Resolution sections
Date: 04-SEP-2007
- State: Resolved
- Updated Contributing Factors and Resolution sections
References
119166-24
119167-24
119168-24
119169-16
119170-16
119171-16
119172-16
122848-09
119173-16
119174-16
119175-16
119176-16
120981-12
120982-12
120983-12
116648-20
116649-20
118202-12
121524-04
125437-07
125438-07
125439-07
125440-01
125441-06
121510-04
126325-02
AttachmentsThis solution has no attachment