There is a vulnerability in IBM® Runtime Environment Java™ Technology Edition, Version 7 that is used by TPF Toolkit.
CVEID: CVE-2016-3426**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE and Java SE Embedded related to the JCE component could allow a remote attacker to obtain sensitive information resulting in a partial confidentiality impact using unknown attack vectors.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112457 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)
TPF Toolkit 4.0.x, and 4.2.x
Product
| VRMF|APAR|Remediation/First Fix
—|—|—|—
TPF Toolkit| 4.2.x| JR56006|
Install the latest version of IBM Installation Manager.
Apply Interim Fix 4.2.7 by using IBM Installation Manager.
Update the Java installation on your z/OS or Linux on z Systems (or both) systems that the TPF Toolkit connects to. Download the latest version of Java from http://www.ibm.com/developerworks/java/jdk/
TPF Toolkit| 4.0.x| JR56007|
Install the latest version of IBM Installation Manager.
Apply Interim Fix 4.0.10 by using IBM Installation Manager.
Update the Java installation on your z/OS or Linux on z Systems (or both) systems that the TPF Toolkit connects to. Download the latest version of Java from http://www.ibm.com/developerworks/java/jdk/