Lucene search

K
ibmIBM4E1A6D56C508FD7134ECAA84163391BD4D519A0BF76FBDC0190A72575B641769
HistoryJun 17, 2018 - 12:16 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime Version 7 affect IBM Content Collector for SAP Applications (CVE-2016-3426 CVE-2016-0264)

2018-06-1712:16:12
www.ibm.com
6

EPSS

0.023

Percentile

89.8%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7 that is used by IBM Content Collector for SAP Applications. These issues were disclosed as part of the IBM Java SDK updates in April 2016.

Vulnerability Details

CVEID: CVE-2016-3426 DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information resulting in a partial confidentiality impact using unknown attack vectors.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112457 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVEID: CVE-2016-0264 DESCRIPTION: A buffer overflow vulnerability in the IBM JVM facilitates arbitrary code execution under certain limited circumstances.
CVSS Base Score: 5.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110867 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

IBM Content Collector for SAP Applications V3.0

IBM Content Collector for SAP Applications V4.0

Remediation/Fixes

IBM provides patches for the affected version. Follow the installation instructions in the README files that is included in the patch.

Product VRMF APAR Remediation/First Fix
IBM Content Collector for SAP Applications 3.0.0 HE12550 Apply JRE Update 3.0.0.2-ICCSAP-Server-JRE-7.0.9.40, and 3.0.0.2-ICCSAP-Client-JRE-7.0.9.40, which are available from Fix Central
For the download details, see <http://www.ibm.com/support/docview.wss?uid=swg24042477&gt;.
IBM Content Collector for SAP Applications 4.0.0 HE12549 Apply JRE Update 4.0.0.1-ICCSAP-Base-JRE-7.0.9.40, which is available from Fix Central
For the download details, see
<http://www.ibm.com/support/docview.wss?uid=swg24042478&gt;.

Workarounds and Mitigations

None.