Lucene search

K
ibmIBM6BFD16D63442859392E4F0B2D9FB127917A0595E1BD96F1625C66401F72732D9
HistoryJul 10, 2019 - 12:40 p.m.

Security Bulletin: The IBM Runtime Environment Java Version 8 used by Transparent Cloud Tiering has a vulnerability which disclosed as part of the IBM Java SDK updates in April 2019

2019-07-1012:40:01
www.ibm.com
11

EPSS

0.003

Percentile

71.9%

Summary

The IBM Runtime Environment Java Version 8 used by Transparent Cloud Tiering has a vulnerability which disclosed as part of the IBM Java SDK updates in April 2019. Transparent Cloud Tiering has addressed the applicable vulnerability.

Vulnerability Details

CVEID: CVE-2019-2602 DESCRIPTION: An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159698&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Transparent Cloud Tiering 1.1.1.0 thru 1.1.3.9
Transparent Cloud Tiering 1.1.5.0 thru 1.1.7.0

Remediation/Fixes

For Transparent Cloud Tiering 1.1.1.0 thru 1.1.3.9 , apply Transparent Cloud Tiering 1.1.3.10 bundled with IBM Spectrum Scale V4.2.3.16 available from FixCentral at:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.2.3&platform=All&function=all

For Transparent Cloud Tiering 1.1.5.0 thru 1.1.7.0, apply Transparent Cloud Tiering 1.1.7.1 bundled with IBM Spectrum Scale V5.0.3.1 available from FixCentral at:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=5.0.3&platform=All&function=all

Workarounds and Mitigations

None