Lucene search

K
ibmIBMACEE11276D8DE933A63412372A9C9AAFD627276A14118DFF83407EEBD68198C8
HistoryNov 27, 2020 - 6:38 p.m.

Security Bulletin: Vulnerability in IBM Java SDK affect IBM Content Classification

2020-11-2718:38:02
www.ibm.com
22

0.001 Low

EPSS

Percentile

39.0%

Summary

There is vulnerability in IBM® SDK Java Technology Edition, Version 6 and IBM® Runtime Environment Java Version 7 used by IBM Content Classification. These issues were disclosed as part of the IBM Java SDK updates in Jul 2020.

Vulnerability Details

CVEID:CVE-2020-14621
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JAXP component could allow an unauthenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185099 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Content Classification 8.8

Remediation/Fixes

Product VRMF Remediation/First Fix
IBM Content Classification 8.8.0.3 Apply Interim Fix 8.8.0.3 IF0019,available from Fix Central

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm content classificationeq8.8