There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 6 and 7 that is used by IBM Installation Manager and IBM Packaging Utility. These issues were disclosed as part of the IBM Java SDK updates in July 2015.
CVEID: CVE-2015-2625**
DESCRIPTION:** An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104743 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)
CVEID: CVE-2015-1931**
DESCRIPTION:** IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
CVSS Base Score: 2.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/102967> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N)
IBM Installation Manager and IBM Packaging Utility versions 1.8.3 and earlier.
Product
| VRMF| APAR| Remediation/First Fix
—|—|—|—
IBM Installation Manager and IBM Packaging Utility| 1.7.4.x | None| 1.7.4.4 IBM Installation Manager Remediation_
_1.7.4.4 IBM Packaging Utility Remediation
Please note that the 1.7.4.4 fix is intended for upgrade of 1.7.4.3 and earlier versions which continue support on platforms that are NOT supported by 1.8 or later versions.
Users running 1.7.4.3 or earlier version on platforms that ARE supported by 1.8.x version, should upgrade to 1.8.4.
IBM Installation Manager and IBM Packaging Utility| 1.8.x| None| 1.8.4 IBM Installation Manager Remediation_
_1.8.4 IBM Packaging Utility Remediation
Upgrade products to the remediated versions per the table above.