Lucene search

K
ibmIBM990671D9FC1F33C711520B044AB507B06634BBD8AE4AAACA9CB49BF8702F7CBC
HistoryMar 18, 2021 - 6:42 p.m.

Security Bulletin: Vulnerability in IBM Java Runtime Environment affects installation and uninstallation of IBM Spectrum Protect for Enterprise Resource Planning on AIX and Linux (CVE-2020-27221)

2021-03-1818:42:13
www.ibm.com
13
ibm java runtime environment
ibm spectrum protect
enterprise resource planning
aix
linux
cve-2020-27221
vulnerability
stack-based buffer overflow
remote attackers
arbitrary code
application crash

EPSS

0.004

Percentile

74.6%

Summary

A vulnerability in IBM Java Runtime Environment may affect the installation and uninstallation of IBM Spectrum Protect for Enterprise Resource Planning (ERP) on AIX and Linux. This issue was disclosed as part of the IBM Java SDK updates in January 2021. UPDATED: 18 March 2021 - Corrected Remediation/Fixes Instructions to include correct paths for SAP HANA and Db2.

Vulnerability Details

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP HANA
8.1.0.0-8.1.11.0
7.1.3.0-7.1.3.2

IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Db2
| 8.1.0.0-8.1.11.0
7.1.3.0-7.1.3.4

IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Oracle
| 8.1.0.0-8.1.11.0
7.1.3.0-7.1.3.4

Remediation/Fixes

The IBM Java Runtime Environment (JRE) shipped with IBM Spectrum Protect for Enterprise Resource Planing (ERP) on AIX and Linux may be affected by CVE-2020-27221. IBM Spectrum Protect for ERP ONLY uses the JRE duringinstallation and uninstallation of the product. During normal operation of IBM Spectrum for ERP, the JRE is not used. To make sure this vulnerability can not be exploited, the JRE should be deleted.

On AIX remove one of the following folders:

  • For DB2, remove /usr/tivoli/tsm/tdp_r3/db264/jre

  • For Oracle, remove /usr/tivoli/tsm/tdp_r3/ora64/jre

On Linux, remove one of the following folders:

  • For Db2, remove /opt/tivoli/tsm/tdp_r3/db264/jre

  • For SAP HANA, remove /opt/tivoli/tsm/tdp_hana/jre

  • For Oracle, remove /opt/tivoli/tsm/tdp_r3/ora64/jre

All backup and restore operations can continue without any impact. If you need to uninstall IBM Spectrum Protect for ERP, you must first install an IBM JRE at level 8.0.6.25 or higher as the system JRE. The uninstallation process can then be performed without any restrictions. Future updates of IBM Spectrum Protect for ERP will contain a JRE that is not affected by CVE-2020-27221.

Workarounds and Mitigations

None

EPSS

0.004

Percentile

74.6%

Related for 990671D9FC1F33C711520B044AB507B06634BBD8AE4AAACA9CB49BF8702F7CBC