Lucene search

K
ibmIBM53458B006608B4F8787503F6477A1196F9DE5CB5BE72977C9E309D97FAC942AD
HistoryApr 07, 2021 - 11:24 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect Rational Business Developer

2021-04-0723:24:47
www.ibm.com
26
ibm java sdk
runtime environment
rational business developer
cve-2020-14797
cve-2020-14779
vulnerabilities
fixes

EPSS

0.003

Percentile

68.5%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 8 and IBM® Runtime Environment Java™ Version 8 used by Rational Business Developer. Rational Business Developer has addressed the applicable CVEs. These issues were disclosed as part of the IBM Java SDK and Runtime Environment updates in the Oracle October 2020 Critical Patch Update minus CVE-2020-14781 and CVE-2020-14782.

Vulnerability Details

CVEID:CVE-2020-14797
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190115 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2020-14779
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190097 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
RBD 9.5
RBD 9.6

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation / First Fix

|

File Name


—|—|—|—|—

Rational Business Developer

|

9.5.x

|

None

| https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ERational&product=ibm/Rational/Rational+Business+Developer&release=9.5.1.2&platform=All&function=all| RBD_9.5_IBM_JDK8_SR6_FP25

Rational Business Developer

|

9.6.x

|

None

|

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ERational&product=ibm/Rational/Rational+Business+Developer&release=9.6&platform=All&function=all

| RBD_9.6_IBM_JDK8_SR6_FP25

Workarounds and Mitigations

None