Lucene search

K
ibmIBM7DC9D25CC96F29D38278D0760C27E8F01358B6CEB48793917719E0F716EBD139
HistoryJul 24, 2020 - 10:49 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Sterling Connect:Direct FTP+ (CVE-2016-3426)

2020-07-2422:49:37
www.ibm.com
13

EPSS

0.007

Percentile

80.3%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7.0.9.30 and 6.0.16.20 that are used by IBM Sterling Connect:Direct FTP+. These issues were disclosed as part of the IBM Java SDK updates in April 2016.

Vulnerability Details

CVEID: CVE-2016-3426** *DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information resulting in a partial confidentiality impact using unknown attack vectors.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112457 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities are applicable to your code. For a complete list of vulnerabilities please refer to the Reference section for more information.

Affected Products and Versions

IBM Sterling Connect:Direct FTP+ 1.3.0

Remediation/Fixes

V.R.M

| APAR|Remediation
—|—|—
1.3.0| IT17607| Apply 1.3.0 Fix005, available on Fix Central.

Workarounds and Mitigations

None