{"product_id":10157,"v_id":10157,"product_name":"IBM WebSphere Federation Server v.9.1","certification_status":"Not Certified","certification_date":"2007-05-25T00:05:00Z","tech_type":"DBMS","vendor_id":{"name":"IBM Corporation","website":"https://www.ibm.com"},"vendor_poc":"Walter Alvey","vendor_phone":"408-463-2475","vendor_email":"alvey@us.ibm.com","assigned_lab":{"cctl_name":"Leidos Common Criteria Testing Laboratory"},"product_description":"<p>IBM DB2 Enterprise Server 9.1.1 with IBM WebSphere Federation Server, v9.1 and Fix Pack 1C</p>\r\n<p>Henceforth, the above components are referred to as the TOE.</p>\r\n<p>WebSphere Federation Server (FS) is middleware product provided by IBM (Silicon Valley Lab) located on 555 Bailey Ave., San Jose, CA.</p>\r\n<p>In the evaluation configuration, the TOE can be installed upon</p>\r\n<ul>\r\n    <li>AIX 5.3</li>\r\n    <li>Red hat Linux (RHEL 4)</li>\r\n</ul>\r\n<p>As middleware (with an embedded RDBMS), WebSphere FS supports the Structured Query Language (SQL) interface from a client that is connected to the server. From the client, commands can be entered interactively or through an executing program to the server to create databases, database tables, and to store and retrieve information from tables either in the embedded DB2 instance or in other associated data sources.</p>\r\n<p>WebSphere FS relies upon the IT Environment to authenticate users before access is allowed and to provide a reliable time source.</p>\r\n<p>WebSphere FS enforces the following security functions: Access Control, Identification and Authentication, Audit, Security Management, and TOE Protection.  WebSphere FS supports User Data protection by controlling access to the database and objects within the database (e.g. views) based upon user and object security attributes. Additionally, WebSphere FS supports User Data protection by restricting the flow of information based upon security labels assigned to users and objects. WebSphere FS also includes the ability to control who can pass requests to other data sources (via the wrappers) and who can access credentials that might be associated with other data sources.</p>\r\n<p>WebSphere FS requires all users to be identified and authenticated before allowing them access to WebSphere FS resources. The IT Environment performs the actual authentication and association of users with groups and passes the result to WebSphere FS.  WebSphere FS audits security relevant events such as access to database resources, changing of security attributes, and modification of security attributes.   Management of the WebSphere FS TOE, including the ability to select and review audit records, is restricted to authorized administrators based on authorities. Management of WebSphere FS objects is restricted to those users that are assigned the appropriate privileges to do so. WebSphere FS is designed so that each of its interfaces performs the necessary access checks before allowing access to WebSphere FS resources.</p>\r\n<p style=\"margin: 0pt;\" class=\"MsoNormal\">There are several IBM WebSphere FS product versions included in the evaluated configuration and the differences have no affect on the security functions claimed in the Security Target. The various WebSphere FS editions differ primarily in the number of resources (e.g., users) they support and are identical in terms of their security architecture and behavior.</p>","evaluation_configuration":null,"security_evaluation_summary":"<p>The evaluation was carried out in accordance to the Common Criteria Evaluation and Validation Scheme (CCEVS) process and scheme. The evaluation demonstrated that IBM WebSphere FS meets the security requirements contained in the &ldquo;IBM Corporation WebSphere Federation Server v9.1 Security Target&rdquo;.  The criteria against which IBM WebSphere FS was judged are described in the Common Criteria for Information Technology Security Evaluation Version 2.3 and the International Interpretations effective as of January, 2006.  The evaluation methodology used by the evaluation team to conduct the evaluation is the Common Methodology for Information Technology Security Evaluation Version 2.3 and Part 2: Evaluation Methodology, Supplement: ALC_FLR - Flaw Remediation, Version 1.1, February 2002, CEM-2001/0015R.  Science Application International Corporation (SAIC) determined that the evaluation assurance level (EAL) for the IBM WebSphere FS TOE is EAL 4 augmented with ALC_FLR.1.  The TOE, configured as specified in the installation guide, satisfies all of the security functional requirements stated in the Security Target.  A validator on behalf of the CCEVS Validation Body monitored the evaluation carried out by SAIC.  The evaluation was completed in May 2007.  Results of the evaluation can be found in the Common Criteria Evaluation and Validation Scheme Validation Report for IBM WebSphere FS prepared by CCEVS.</p>","environmental_strengths":"<p>IBM WebSphere FS is a commercial network product that provides identification and authentication, user data protection, audit, security management, and TOE protection.  IBM WebSphere FS provides a level of protection that is appropriate for IT environments that require that access is controlled to the database and its contents where the IBM TOE is appropriately protected from physical attacks.</p>","features":[]}