Lucene search

K
ibmIBM6FAC9F4256F04C82C56B707045A05BB8FAFC06A451C07135CC51DDBA7CFB9091
HistoryJul 15, 2021 - 12:58 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK (January 2021) affect IBM InfoSphere Information Server

2021-07-1500:58:53
www.ibm.com
114
ibm java sdk
ibm infosphere information server
remote attackers
arbitrary code
application crashes
sensitive information

EPSS

0.004

Percentile

75.0%

Summary

There are multiple vulnerabilities in the IBM® SDK Java™ Technology Edition, Versions 7 and 8 that are used by IBM InfoSphere Information Server. These issues were disclosed as part of the IBM Java SDK updates in January 2021.

Vulnerability Details

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2020-14782
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190100 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID:CVE-2020-14781
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JNDI component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190099 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Information Server 11.7
InfoSphere Information Server 11.5

Remediation/Fixes

Product VRMF APAR Remediation/First Fix

InfoSphere Information Server, Information Server on Cloud

|

11.7

|

JR63308

|

--Follow instructions in the README
--See Technote for class not found errors related to ProviderExceptions, Failed to initialize IBMJCEPlus provider, and jgskit (Not found in java.library.path)

InfoSphere Information Server, Information Server on Cloud

|

11.5

|

JR63308

|

--Follow instructions in the README

Workarounds and Mitigations

None

EPSS

0.004

Percentile

75.0%

Related for 6FAC9F4256F04C82C56B707045A05BB8FAFC06A451C07135CC51DDBA7CFB9091