Lucene search

K
ibmIBM35EC921ED8E86A98FEDD3951DBB5567B30D12EC279DD10392816CD8646A204B3
HistorySep 05, 2018 - 12:26 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect Enterprise Content Management System Monitor

2018-09-0512:26:23
www.ibm.com
10

0.003 Low

EPSS

Percentile

71.3%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 7 used by Enterprise Content Management System Monitor. These issues were disclosed as part of the IBM® SDK Java™ Technology Edition Quarterly CPU - Jan 2018 - Includes Oracle Jan 2018 CPU.

Vulnerability Details

CVEID:CVE-2018-2603 **DESCRIPTION:*An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137855&gt;for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2018-2618 **DESCRIPTION:*An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JCE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 5.9
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137870&gt;for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Enterprise Content Management System Monitor v5.2

Remediation/Fixes

Enterprise Content Management System Monitor 5.2.0.5.002 Fix Central

Workarounds and Mitigations

N/A