Lucene search

K
ibmIBM783DFDEAA635B31447A0BABCE76FD2BF22ACC55CF3D56346DE06D34BBCA763A7
HistoryJun 15, 2018 - 7:06 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affects IBM Workload Deployer. (CVE-2016-3426 and CVE-2016-0264)

2018-06-1507:06:02
www.ibm.com
11

EPSS

0.023

Percentile

89.8%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 6 that is used by IWD Workload Deployer. These issues were disclosed as part of the IBM Java SDK updates in April 2016.

Vulnerability Details

CVEID: CVE-2016-3426** *DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information resulting in a partial confidentiality impact using unknown attack vectors.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112457 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVEID: CVE-2016-0264** *DESCRIPTION: A buffer overflow vulnerability in the IBM JVM facilitates arbitrary code execution under certain limited circumstances.
CVSS Base Score: 5.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110867 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

IBM Workload Deployer version 3.1 and later

Remediation/Fixes

The solution is to apply the following IBM Workload Deployer fix:

Upgrade the IBM Workload Deployer to the following fix level:

Product

|

VRMF

|

Remediation/First Fix

—|—|—
IBM Workload Deployer System| Release V3.1.0.7| V3.1.0.7 Interim fix12,

http://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=ibm~WebSphere&product=ibm/WebSphere/IBM+Workload+Deployer&release=3.1.0.7&platform=All&function=fixId&fixids=3.1.0.7-ifix12-IBM_Workload_Deployer&includeRequisites=1&includeSupersedes=0

Workarounds and Mitigations

None