Lucene search

K
ibmIBM56D260CC4CB1C373F5B3A09E23A8EB605DFE76F08A09790707C7E16F916F4E6F
HistoryMar 23, 2021 - 10:13 p.m.

Security Bulletin: Multiple Vulnerabilities in IBM Java Runtime Affect IBM Sterling Connect:Direct for UNIX

2021-03-2322:13:43
www.ibm.com
23

0.003 Low

EPSS

Percentile

71.8%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 8.0.6.0, 8.0.5.40, 8.0.5.35, 8.0.5.30, and 7.0.10.40, used by IBM Sterling Connect:Direct for UNIX. IBM Sterling Connect:Direct for UNIX has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2020-14579
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185057 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2020-14578
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185056 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2020-14577
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185055 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2019-17639
**DESCRIPTION:**Eclipse OpenJ9 could allow a remote attacker to obtain sensitive information, caused by the premature return of the current method with an undefined return value. By invoking the System.arraycopy method with a length longer than the length of the source or destination array can, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185437 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Connect:Direct for UNIX 6.0.0
IBM Connect:Direct for UNIX 6.1.0
IBM Sterling Connect:Direct for UNIX 4.3.0
IBM Sterling Connect:Direct for UNIX 4.2.0

Remediation/Fixes

V.R.M.F

| APAR| Remediation/First Fix
—|—|—
6.1.0| IT36111| Apply 6.1.0.3.iFix007, available on Fix Central
6.0.0| IT36111| Apply 6.0.0.2.iFix091, available on Fix Central
4.3.0| IT36111| Apply 4.3.0.1.iFix073, available on Fix Central
4.2.0| IT36111| Apply 4.2.0.5.iFix051, available on Fix Central

Workarounds and Mitigations

None