Lucene search

K
ibmIBM7F0BA7BB5878F7B87EBE99B37D5F57E2F547C48BB31E158736CE02617108C28A
HistoryApr 19, 2021 - 7:06 p.m.

Security Bulletin: IBM SDK, Java Technology Edition Quarterly CPU - Jan 2021 vulnerabilities could affect InfoSphere Streams

2021-04-1919:06:12
www.ibm.com
22
ibm
java
infosphere streams
vulnerability
cve-2020-14803
cve-2020-27221
buffer overflow
fix pack.

EPSS

0.004

Percentile

74.6%

Summary

IBM SDK, Java Technology Edition Quarterly CPU - Jan 2021 vulnerabilities could affect InfoSphere Streams. Please see details below.

Vulnerability Details

CVEID:CVE-2020-14803
**DESCRIPTION:**An unspecified vulnerability in Java SE could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190121 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Streams 4.1.1.x
InfoSphere Streams 4.2.1.x
InfoSphere Streams 4.3.1.x

Remediation/Fixes

Apply 4.3.1 Fix Pack 5 (4.3.1.5) or higher .

Workarounds and Mitigations

None