Lucene search

K
ibmIBM055125DDCC24FED6338E6230B841A6E09BEF122BD1DAAD92C212B50D47EC635A
HistoryJun 15, 2018 - 7:03 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Image Construction and Composition Tool (CVE-2015-0410 and CVE-2014-6593)

2018-06-1507:03:24
www.ibm.com
19

EPSS

0.698

Percentile

98.1%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition Version 6 and 7 that are used by IBM Image Construction and Composition Tool. These issues were disclosed as part of the IBM Java SDK updates in January 2015.

Vulnerability Details

CVEID: CVE-2015-0410**
DESCRIPTION:** An unspecified vulnerability related to the Security component could allow a remote attacker to cause a denial of service.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100151 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVEID: CVE-2014-6593**
DESCRIPTION:** An unspecified vulnerability related to the JSSE component has partial confidentiality impact, partial integrity impact, and no availability impact.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/100153 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N)

Affected Products and Versions

IBM Image Construction and Composition Tool v2.2.1.3
IBM Image Construction and Composition Tool v2.3.1.0
IBM Image Construction and Composition Tool v2.3.2.0

Remediation/Fixes

The solution is to apply the following IBM Image Construction and Composition Tool version fixes.

Upgrade the IBM Image Construction and Composition Tool to the following fix levels:

* For IBM Image Construction and Composition Tool v2.2.1.3
  * IBM Image Construction and Composition Tool v2.2.1.3 Build 28

http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=PureSystems&product=ibm/WebSphere/PureApplication+System&release=1.1.0.5&platform=All&function=fixId&fixids=ICCT_efix_Repository_2.2.1.3-28&includeSupersedes=0
* For IBM Image Construction and Composition Tool v2.3.1.0
* IBM Image Construction and Composition Tool v2.3.1.0 Build 38

http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=PureSystems&product=ibm/WebSphere/PureApplication+System&release=2.0.0.1&platform=All&function=fixId&fixids=ICCT_efix_Repository_2.3.1.0-38&includeSupersedes=0
* For IBM Image Construction and Composition Tool v2.3.2.0
* IBM Image Construction and Composition Tool v2.3.2.0 Build 12

http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=PureSystems&product=ibm/WebSphere/PureApplication+System&release=2.1.0.0&platform=All&function=fixId&fixids=ICCT_efix_Repository_2.3.2.0-12&includeSupersedes=0

Workarounds and Mitigations

None