Interstage Application Server: Vulnerability may allow access from a non-permitted IP address. November 30th, 2010


Notes on using this web page

1. Description

When the access is restricted by IP address, the request from a non-permitted IP address may be accepted.

2. Impact

Though a specific impact depends on a system function, there is a possibility of information disclosure because the request from an unauthorized client may be acceptted.

3. Affected systems and corresponding action

3-1. Affected systems:

GP7000F, PRIMEPOWER, SPARC Enterprise, PRIMERGY, GP5000, CELSIUS, FMV series, AT compatible machines, PRIMEQUEST

3-2. Affected products and required patch

Interstage Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Application Server Enterprise Edition6.0Solaris 7/ 8/ 9FJSVjs4None*
Interstage Application Server Enterprise Edition7.0Solaris 8/ 9FJSVjs4None*
Interstage Application Server Enterprise Edition7.0.1Solaris 8/ 9/ 10FJSVjs4None*
Interstage Application Server Enterprise EditionV8.0.0Solaris 9/ 10FJSVjs4None*
Interstage Application Server Enterprise EditionV8.0.2Solaris 9/ 10FJSVjs4None*
Interstage Application Server Standard-J EditionV8.0.0Solaris 9/ 10FJSVjs4None*
Interstage Application Server Standard-J EditionV8.0.2Solaris 9/ 10FJSVjs4None*
Interstage Application Server Plus7.0Solaris 8/ 9FJSVjs4None*
Interstage Application Server Plus7.0.1Solaris 8/ 9/ 10FJSVjs4None*
Interstage Application Server Enterprise Edition for WindowsV6.0Windows Server 2003/ Windows 2000 Server/ Windows NT Server 4.0F3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV7.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV7.0.1Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV8.0.1Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV8.0.2Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV9.0.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV9.0.0AWindows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Standard-J Edition for WindowsV8.0.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Standard-J Edition for WindowsV8.0.1Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Standard-J Edition for WindowsV8.0.2Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Standard-J Edition for WindowsV9.0.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Standard-J Edition for WindowsV9.0.0AWindows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Plus for WindowsV6.0Windows Server 2003/ Windows 2000 Server/ Windows NT Server 4.0F3FMjs4None*
Interstage Application Server Plus for WindowsV7.0Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Plus for WindowsV7.0.1Windows Server 2003/ Windows 2000 ServerF3FMjs4None*
Interstage Application Server Plus Developer for WindowsV6.0Windows Server 2003/ Windows 2000 Server/ Windows XP/ Windows NT Server 4.0F3FMjs4None*
Interstage Application Server Plus Developer for WindowsV7.0Windows Server 2003/ Windows 2000 Server/ Windows XPF3FMjs4None*
Interstage Application Server Enterprise Edition for WindowsV8.0.0Windows Server 2003(IPF)F3FMjs4None*
Interstage Application Server Enterprise Edition for LinuxV6.0RHEL-AS3(x86)/ ES3(x86)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4None*
Interstage Application Server Standard-J Edition for LinuxV8.0.0RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4None*
Interstage Application Server Standard-J Edition for LinuxV8.0.2RHEL-AS4(x86)/ AS4(EM64T)FJSVjs4None*
Interstage Application Server Plus for LinuxV7.0RHEL-AS3(x86)/ ES3(x86)FJSVjs4None*
Interstage Application Server Plus for LinuxV7.0.1RHEL-AS3(x86)/ ES3(x86)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV7.0RHEL-AS4(IPF)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV8.0.0RHEL-AS4(IPF)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV8.0.1RHEL-AS4(IPF)FJSVjs4None*
Interstage Application Server Enterprise Edition for LinuxV8.0.2RHEL-AS4(IPF)FJSVjs4None*
Interstage Apworks/Studio
ProductsVersionTarget OSPackage namePatch ID.
Interstage Apworks Modelers-J Edition for WindowsV6.0Windows 2000 Server/ Windows XPF3FMjs4None*
Interstage Apworks Modelers-J Edition for WindowsV6.0AWindows 2000 Server/ Windows XPF3FMjs4None*
Interstage Apworks Modelers-J Edition for WindowsV7.0Windows Server 2003/ Windows 2000 Server/ Windows XPF3FMjs4None*
Interstage Studio Enterprise Edition for Windows8.0.1Windows Server 2003/ Windows 2000 Server/ Windows XPF3FMjs4None*
Interstage Studio Standard-J Edition for Windows8.0.1Windows Server 2003/ Windows 2000 Server/ Windows XPF3FMjs4None*
Interstage Business Application Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Business Application Server Enterprise Edition for Linux8.0.0RHEL-AS4(IPF)FJSVjs4None*
Interstage Job Workload Server
ProductsVersionTarget OSPackage namePatch ID.
Interstage Job Workload Server for Linux8.1.0RHEL-AS4(IPF)FJSVjs4None*


* For the solution, please refer to "3-3. Workaround".

Note: Determining the affected product

  • [V6 series]
    • Solaris
      To see package information on the FJSVisas package, the following command can be run:
        pkginfo -l FJSVisas
    • Windows
      See the title in the Software Release Guide.
        [Start]
          -> [Program]
            -> [Interstage]
              -> [Application Server | Apworks]
                -> [Software Release Guide]
    • Linux
      To see package information on the FJSVisas package, the following command can be run:
        rpm -q FJSVisas
  • [V7 series or later]
    Use the isprintvl command.
      isprintvl

3-3. Workaround

Adopt security measures against requests from invalid IP addresses or invalid requests accessing to Servlet container ports directly. The security measures are done by a firewall and so on.
Specifically, connections to Servlet container ports should be rejected except for the request from Web server (Web server connector). Security measures against internal threats that are connections to Servlet container ports from intranet should also be done robustly by system configurations and operations.

4. Related information

None.

5. Revision history

  • November 30th, 2010: 2nd release
    • In "3. Corresponding system and Patch information", "Patch ID" was changed to "None".
    • "3-3. Workaround" was added.
  • November 19th, 2010: Initial release

Top of Page