A vulnerability in IBM Java Runtime Environment may affect the installation and uninstallation of IBM Spectrum Protect for Enterprise Resource Planning (ERP) on AIX and Linux. This issue was disclosed as part of the IBM Java SDK updates in January 2021. UPDATED: 18 March 2021 - Corrected Remediation/Fixes Instructions to include correct paths for SAP HANA and Db2.
CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP HANA | |
8.1.0.0-8.1.11.0 | |
7.1.3.0-7.1.3.2 |
IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Db2
| 8.1.0.0-8.1.11.0
7.1.3.0-7.1.3.4
IBM Spectrum Protect for Enterprise Resource Planning: Data Protection for SAP for Oracle
| 8.1.0.0-8.1.11.0
7.1.3.0-7.1.3.4
The IBM Java Runtime Environment (JRE) shipped with IBM Spectrum Protect for Enterprise Resource Planing (ERP) on AIX and Linux may be affected by CVE-2020-27221. IBM Spectrum Protect for ERP ONLY uses the JRE duringinstallation and uninstallation of the product. During normal operation of IBM Spectrum for ERP, the JRE is not used. To make sure this vulnerability can not be exploited, the JRE should be deleted.
On AIX remove one of the following folders:
For DB2, remove /usr/tivoli/tsm/tdp_r3/db264/jre
For Oracle, remove /usr/tivoli/tsm/tdp_r3/ora64/jre
On Linux, remove one of the following folders:
For Db2, remove /opt/tivoli/tsm/tdp_r3/db264/jre
For SAP HANA, remove /opt/tivoli/tsm/tdp_hana/jre
For Oracle, remove /opt/tivoli/tsm/tdp_r3/ora64/jre
All backup and restore operations can continue without any impact. If you need to uninstall IBM Spectrum Protect for ERP, you must first install an IBM JRE at level 8.0.6.25 or higher as the system JRE. The uninstallation process can then be performed without any restrictions. Future updates of IBM Spectrum Protect for ERP will contain a JRE that is not affected by CVE-2020-27221.
None