Lucene search

K
ibmIBM2FAF7A6D577E5A551B34815E630008C9F60A86F3050B6EA1FDE834ECDAD3CDBD
HistoryJun 05, 2019 - 2:15 p.m.

Security Bulletin: IBM MessageSight is affected by the following four IBM Java vulnerabilities

2019-06-0514:15:01
www.ibm.com
17

0.083 Low

EPSS

Percentile

94.4%

Summary

IBM MessageSight has addressed the following Java vulnerabilities:

CVE-2019-2698: An attacker can use a maliciously crafted font to exploit a flaw in the JDK’s font parsing code
CVE-2019-2697: An attacker can use a maliciously crafted font to exploit a flaw in the JDK’s font parsing code
CVE-2019-2602: A flaw in the java.math.BigDecimal API causes hangs when parsing certain String values
CVE-2019-10245: A flaw in the OpenJ9 class verifier potentially allows untrusted code to elevate its privileges and execute arbitrary code

Vulnerability Details

CVEID: CVE-2019-2698 DESCRIPTION: An unspecified vulnerability related to the Java SE 2D component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159790&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2019-2697 DESCRIPTION: An unspecified vulnerability related to the Java SE 2D component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159789&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID: CVE-2019-2602 DESCRIPTION: An unspecified vulnerability related to the Java SE Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159698&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID: CVE-2019-10245 DESCRIPTION: Eclipse OpenJ9 is vulnerable to a denial of service, caused by the execution of a method past the end of bytecode array by the Java bytecode verifier. A remote attacker could exploit this vulnerability to cause the application to crash.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/160010&gt; for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected IBM MessageSight Affected Versions
IBM MessageSight 1.2.0.0 - 1.2.0.3
IBM MessageSight 2.0.0.0 - 2.0.0.2
IBM MessageSight 5.0.0.0
IBM MessageSight 5.0.0.1

Remediation/Fixes

IBM MessageSight | 1.2.0.3 | [

1.2.0.3-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886203&gt;)
—|—|—
IBM MessageSight | 2.0.0.2 | [

2.0.0.2-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886207&gt;)
IBM MessageSight | 5.0.0.0 | [

5.0.0.0-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886211 >)
IBM MessageSight | 5.0.0.1 | [

5.0.0.1-IBM-IMA-IFIT29187

](<http://www.ibm.com/support/docview.wss?uid=ibm10886213&gt;)

Workarounds and Mitigations

None