Lucene search

K
ibmIBM5A383DE2F7BD923DBD014196C32AC20A30552177E420C72B8022D90663655B9F
HistoryMay 24, 2021 - 11:07 a.m.

Security Bulletin: IBM MQ Appliance is affected by a Java SE vulnerability (CVE-2020-27221)

2021-05-2411:07:48
www.ibm.com
14
ibm mq appliance
java se
vulnerability
cve-2020-27221
buffer overflow
security fix
eclipse openj9
apars
it35811
it35540
version 9.2 cd
version 9.2 lts
version 9.1 lts
upgrade

EPSS

0.004

Percentile

74.6%

Summary

IBM MQ Appliance has resolved a Java SE vulnerability.

Vulnerability Details

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.2 CD
IBM MQ Appliance 9.2 LTS
IBM MQ Appliance 9.1 CD
IBM MQ Appliance 9.1 LTS

Remediation/Fixes

This vulnerability is addressed by APARs IT35811 and IT35540

IBM MQ Appliance version 9.1 LTS

Apply iFix IT35811, or later.

IBM MQ Appliance version 9.2 LTS

Apply fixpack 9.2.0.2, or later.

IBM MQ Appliance version 9.1 CD and 9.2 CD

Upgrade to 9.2.2 CD release, or later.

Workarounds and Mitigations

None

EPSS

0.004

Percentile

74.6%

Related for 5A383DE2F7BD923DBD014196C32AC20A30552177E420C72B8022D90663655B9F