Lucene search

K
ibmIBM9FF3831C7E22B3E484BB7DE6DD7B8208547ED4A9D05819AE0271A6E0BA3A8B5D
HistoryJun 16, 2018 - 8:13 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect Financial Transaction Manager for ACH Services, Financial Transaction Manager for Check Services, and Financial Transaction Manager for Corporate Payment Services for Multiplatforms

2018-06-1620:13:29
www.ibm.com
7

0.003 Low

EPSS

Percentile

71.3%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7 used by Financial Transaction Manager (FTM) for ACH Services, Financial Transaction Manager for Check Services, and Financial Transaction Manager for Corporate Payment Services (CPS) for Multiplatforms. These issues were disclosed as part of the IBM Java SDK updates in January 2018.

Vulnerability Details

If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities are applicable to your code. For a complete list of vulnerabilities please refer to the link for “IBM Java SDK Security Bulletin" located in the “References” section for more information.

CVEID: CVE-2018-2579**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Libraries component could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base Score: 3.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137833&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2018-2602**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded I18n component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and low availability impact.
CVSS Base Score: 4.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137854&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L)

CVEID: CVE-2018-2599**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JNDI component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and low availability impact.
CVSS Base Score: 4.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137851&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)

CVEID: CVE-2018-2603**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137855&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2018-2633**
DESCRIPTION:** An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JNDI component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/137885&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

- FTM for ACH Services v3.0.2.0 - v3.0.2.1, v3.0.5.0, v3.1.0.0-3.1.0.1

- FTM for Check Services v3.0.0.n, v3.0.2.0 - v3.0.2.1, v3.0.5.0

- FTM for CPS v3.0.2.0 - v3.0.2.1

Remediation/Fixes

Product

| VRMF| APAR| Remediation/First Fix
—|—|—|—
FTM for ACH Services| 3.0.2.0 - 3.0.2.1, 3.0.5.0, 3.1.0.0-3.1.0.1| PI95439| 3.0.2 apply 3.0.2.1-FTM-ACH-MP-iFix0010 or later.
3.0.5 apply 3.0.5.0-FTM-ACH-MP-iFix0001 or later.
3.1.0 apply 3.0.1.1-FTM-ACH-MP-iFix0001 or later.

Product VRMF APAR Remediation/First Fix
FTM for Check Services 3.0.0.n
3.0.2.0 - 3.0.2.1, 3.0.5.0 PI95439 3.0.0 apply 3.0.0.15-FTM-Check-MP-iFix0014 or later.
3.0.2 apply 3.0.2.1-FTM-Check-MP-iFix0010 or later.
3.0.5 apply 3.0.5.0-FTM-Check-MP-iFix0001 or later.
Product VRMF APAR Remediation/First Fix
FTM for CPS 3.0.2.0 - 3.0.2.1 PI95439 3.0.2 apply 3.0.2.1-FTM-CPS-MP-iFix0010 or later.

Workarounds and Mitigations

None