Lucene search

K
ibmIBM0444E52FAB9025773782E5354A2FB187FF6E7E569F4F47BA159D2326A0D1F77E
HistoryJul 17, 2020 - 12:03 p.m.

Security Bulletin: IBM SDK, Java Technology Edition Quarterly CPU - Jan 2020 - Includes Oracle Jan 2020 CPU affect IBM Content Classification

2020-07-1712:03:32
www.ibm.com
21

0.003 Low

EPSS

Percentile

68.8%

Summary

There is vulnerability in IBM® Runtime Environment Java™ Version 6 and Java™ 7 that is used by IBM Content Classification. This issue was disclosed as part of the IBM Java SDK updates in Jan 2020.

Vulnerability Details

CVEID:CVE-2020-2583
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174531 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Content Classification 8.8

Remediation/Fixes

Product

| VRM| Remediation
—|—|—
IBM Content Classification| 8.8| Use IBM Content Classification 8.8.8 Interim Fix 0018

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm content classificationeq8.8