IBM InfoSphere Identity Insight, Version 8.1 ISII IEHS Fix Readme July 2012 Contents: ========= 1.Problems/issues addressed in this hotfix 2.Known issues 3.Prerequisites 4.Implementation steps 5.Install verification *************************************************************************** 1.Problems/issues addressed in this fix: =========================================== This hotfix is for IBM InfoSphere Identity Insight v8.1.0 users who and have installed the information center and IBM Eclipse Help System (IEHS). A vulnerability was found in the IEHS WAR that can permit a local user to exploit and gain escalated privilege. *************************************************************************** 2. Known issues: ================= None *************************************************************************** 3. Prerequisites: ================= IBM InfoSphere Identity Insight Version 8.1.0 with the Information Center installed. ******************************************************************************** 4. Implementation steps ======================= To apply the hotfix, please do the following: 1. Copy the required files to your hard drive. 2. Stop the pipelines. 3. Stop the IBM Identity Insight application by running the StopEAS script. 4. Make a copy of the following files as a backup: a).[DRIVE]:\was-apps\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.webapp_3.3.100.v20080528\advanced\deferredView.jsp b).[DRIVE]:\was-apps\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.webapp_3.3.100.v20080528\advanced\searchView.jsp c).[DRIVE]:\was-apps\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.base_3.3.100.v20080617\helpbase.jar 5. Replace the files from Step 3 with the updated files in the patch by copying the new versions into bin: a). identityinsightv8r1_iehswar343_securitypatch.zip\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.webapp_3.3.100.v20080528\advanced\deferredView.jsp b). identityinsightv8r1_iehswar343_securitypatch.zip\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.webapp_3.3.100.v20080528\advanced\searchView.jsp c). identityinsightv8r1_iehswar343_securitypatch.zip\ibm-is-ii-documentation.ear\webapp.war\WEB-INF\eclipse\plugins\org.eclipse.help.base_3.3.100.v20080617\helpbase.jar 6. Start the pipelines by running the StartEAS script. ************************************************************************ 5. Install verification ======================= Launch the product information center in a Web browser and make sure that content displays correctly.