Lucene search

K
ibmIBMA2D99883140C7F5EE9B1EBEAE7F0540992E04F6263F481DB5289C6F803CF9EC4
HistoryJul 24, 2020 - 10:19 p.m.

Security Bulletin: Java Vulnerability Impacts IBM Control Center (CVE-2018-1656)

2020-07-2422:19:08
www.ibm.com
22

0.002 Low

EPSS

Percentile

58.5%

Summary

There is a vulnerability in IBM® Runtime Environment Java™ Technology Edition, Version 7 and 8 that is used by IBM Control Center. This issue was disclosed as part of the IBM Java SDK updates in July 2018.

Vulnerability Details

**CVEID:** [CVE-2018-1656](<https://vulners.com/cve/CVE-2018-1656>)
**DESCRIPTION:**The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) does not protect
against path traversal attacks when extracting compressed dump files.
CVSS Base Score: 7.4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/144882> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)

Affected Products and Versions

IBM Control Center 5.4.2.1 through 5.4.2.2 iFix03
IBM Control Center 6.0.0.0 through 6.0.0.2 iFix04
IBM Control Center 6.1.0.0 through 6.1.0.2 iFix05
IBM Control Center 6.1.1.0 through 6.1.1.0 iFix04

Remediation/Fixes

Product

|

VRMF

|

iFix

|

APAR

|

Remediation / First Fix

—|—|—|—|—

IBM Control Center

|

5.4.2.2

|

iFix04

|

IT26601

|

Fix Central - 5.4.2.2

IBM Control Center

|

6.0.0.2

|

iFix05

|

IT26601

|

Fix Central - 6.0.0.2

IBM Control Center

|

6.1.0.2

|

iFix06

|

IT26601

|

Fix Central - 6.1.0.2

IBM Control Center

|

6.1.1.0

|

iFix05

|

IT26600

|

Fix Central - 6.1.1.0

Workarounds and Mitigations

None.

CPENameOperatorVersion
ibm control centereqany

0.002 Low

EPSS

Percentile

58.5%

Related for A2D99883140C7F5EE9B1EBEAE7F0540992E04F6263F481DB5289C6F803CF9EC4