Lucene search

K
ibmIBM1C34B058DA6AE438E730A8B5BB4735C7E685A368683AC20C384B4CAFF04FBF1B
HistoryJun 30, 2023 - 2:40 p.m.

Security Bulletin: Vulnerability in IBM Java SDK and IBM Java Runtime affects TPF Toolkit

2023-06-3014:40:20
www.ibm.com
18
ibm java sdk
runtime environment
tpf toolkit
oracle java se
cvss
vulnerability
windows
linux

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

25.9%

Summary

A vulnerability in IBM® SDK Java™ Technology Edition and IBM® Runtime Environment Java™ that is used by TPF Toolkit has been addressed.

Vulnerability Details

CVEID:CVE-2023-21967
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE, Oracle GraalVM Enterprise Edition related to the Hotspot component could allow a remote attacker to cause high confidentiality impact.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/253166 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
TPF Toolkit 4.6

Remediation/Fixes

Product VRMF APAR Remediation/First Fix
TPF Toolkit 4.6 None

Apply the appropriate fix from Fix Central for your platform:

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdb2_content_manager_toolkitMatchany
CPENameOperatorVersion
tpf toolkiteqany

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

25.9%