There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 1.8
used by IBM Sterling Secure Proxy. These issues were disclosed as part of the IBM Java SDK updates in January 2019.
CVEID: CVE-2018-12547 DESCRIPTION: Eclipse OpenJ9 is vulnerable to a buffer overflow, caused by improper bounds checking by the jio_snprintf() and jio_vsnprintf() functions. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base Score: 9.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/157512 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
CVEID: CVE-2018-1890 DESCRIPTION: IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users.
CVSS Base Score: 5.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/152081 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L)
CVEID: CVE-2019-2426 DESCRIPTION: An unspecified vulnerability related to the Java SE Networking component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base Score: 3.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/155744 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.0.0 iFix 1
IBM Sterling Secure Proxy 3.4.3.0 through 3.4.3.2 iFix 4
IBM Sterling Secure Proxy 3.4.2.0 through 3.4.2.0 iFix 17
Product
|
VRMF
|
iFix
|
Remediation/First Fix
—|—|—|—
IBM Secure Proxy
|
6.0.0.0
|
MFT10242
|
IBM Sterling Secure Proxy
|
3.4.3.2
|
MFT10242
|
IBM Sterling Secure Proxy
|
3.4.2.0
|
MFT10242
|
None.