Lucene search

K
ibmIBM07556DC3A5C5A4AEF5439EA47A97F0441A6C937533F20941FD6D1B170F55D397
HistoryAug 09, 2018 - 3:24 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Runtime Environments Java Technology Edition, versions 6, 7, & 8 affect Transformation Extender

2018-08-0903:24:58
www.ibm.com
19

0.002 Low

EPSS

Percentile

59.7%

Summary

There are multiple vulnerabilities in IBM® Runtime Environments Java™ Technology Edition versions 6, 7, & 8 that are used by Transformation Extender. This issue was disclosed as part of the IBM Java SDK updates in July 2017.

Vulnerability Details

CVEID: CVE-2017-10102**
DESCRIPTION:** An unspecified vulnerability related to the Java SE RMI component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128863 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

CVEID: CVE-2017-10115**
DESCRIPTION:** An unspecified vulnerability related to the Java SE JCE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128876 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID: CVE-2017-10116**
DESCRIPTION:** An unspecified vulnerability related to the Java SE Security component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128877 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

  • WebSphere Transformation Extender Design Studio
  • WebSphere Transformation Extender with Command Server
  • WebSphere Transformation Extender for Integration Servers
  • WebSphere Transformation Extender for Application Programming
  • WebSphere Transformation Extender with Launcher
    Transformation Extender versions|CVEs
    —|—
    9.0.0 - 9.0.0.2
    8.4.1 - 8.4.1.5
    8.4.0 - 8.4.0.5
    8.3.0 - 8.3.0.7| CVE-2017-10115
    CVE-2017-10116
    CVE-2017-10102

Remediation/Fixes

All Transformation Extender versions: Download and install the fix for APAR PI87714.

Workarounds and Mitigations

None.

0.002 Low

EPSS

Percentile

59.7%