Lucene search

K
ibmIBM57B2D7521EC7DF40C6C4D1EAEC35430FAFDAC9ECF2870416B8F4209BBC2D59DE
HistoryJul 24, 2020 - 10:19 p.m.

Security Bulletin: IBM Java Runtime Vulnerability Affects IBM Sterling Secure Proxy (CVE-2020-2781)

2020-07-2422:19:08
www.ibm.com
21

0.001 Low

EPSS

Percentile

49.3%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 1.8 used by IBM Sterling Secure Proxy. IBM Sterling Secure Proxy has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2020-2781
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Java SE JSSE component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/179681 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Secure Proxy 6.0.1
IBM Secure Proxy 6.0.0.1
IBM Sterling Secure Proxy 3.4.3.2
IBM Sterling Secure Proxy 3.4.2

Remediation/Fixes

Product

|

VRMF

|

iFix

|

Remediation/First Fix

—|—|—|—

IBM Secure Proxy

|

6.0.1.1

|

-

|

Fix Central

IBM Secure Proxy

|

6.0.0.1

|

_iFix 3
_

|

Fix Central

IBM Sterling Secure Proxy

|

3.4.3.2

|

_iFix 8
_

|

Fix Central

IBM Sterling Secure Proxy

|

3.4.2.0

|

iFix 21

|

Fix Central

Workarounds and Mitigations

None