Lucene search

K
ibmIBM4BAA7DBBD4B519F5509C540F33D2C614C19A50E6429F416A1527257CB1B7FED5
HistoryJul 24, 2020 - 10:19 p.m.

Security Bulletin: Java Vulnerability Impacts IBM Control Center

2020-07-2422:19:08
www.ibm.com
28
ibm control center
java technology
version 7
version 8
cve-2018-2783
vulnerability
security
ibm java sdk
update
affected products
versions
remediation
fixes

EPSS

0.003

Percentile

66.4%

Summary

There is a vulnerability in IBM® Runtime Environment Java™ Technology Edition, Version 7 and 8 that is used by IBM Control Center. The issue was disclosed as part of the IBM Java SDK update in April 2018.

Vulnerability Details

CVEID: CVE-2018-2783 DESCRIPTION: An unspecified vulnerability related to the Java SE Security component could allow an unauthenticated attacker to cause high confidentiality impact, high integrity impact, and no availability impact.
CVSS Base Score: 7.4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/141939&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

IBM Control Center 5.4.2.1 through 5.4.2.2 iFix02
IBM Control Center 6.0.0.0 through 6.0.0.2 iFix03
IBM Control Center 6.1.0.0 through 6.1.0.2 iFix04
IBM Control Center 6.1.1.0 through 6.1.1.0 iFix03

Remediation/Fixes

Product

|

VRMF

|

iFix

|

Remediation / First Fix

—|—|—|—
IBM Control Center | 5.4.2.2 | iFix03 | Fix Central - 5.4.2.2
IBM Control Center | 6.0.0.2 | iFix04 | Fix Central - 6.0.0.2
IBM Control Center | 6.1.0.2 | iFix05 | Fix Central - 6.1.0.2
IBM Control Center | 6.1.1.0 | iFix04 | Fix Central - 6.1.1.0

Workarounds and Mitigations

None.

EPSS

0.003

Percentile

66.4%