Lucene search

K
ibmIBMB0639A1477DD788A0606084BA43F1623AB2FBFC72AAF52F2452C04CC5FF9DAE5
HistoryMar 23, 2022 - 3:43 p.m.

Security Bulletin: A vulnerability in Java affects IBM License Metric Tool v9 (CVE-2021-35550).

2022-03-2315:43:48
www.ibm.com
31

0.002 Low

EPSS

Percentile

65.1%

Summary

IBM License Metric Tool is vulnerable to attacks related to Java TLS vulnerability.

Vulnerability Details

CVEID:CVE-2021-35550
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211627 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM License Metric Tool All

Remediation/Fixes

Upgrade ILMT Server to version 9.2.27 or later using the following procedure:
<https://www.ibm.com/docs/en/license-metric-tool?topic=tool-upgrading-latest-version&gt;

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm license metric tooleq9.2