Lucene search

K
ibmIBMB3AF98515AF4AC67A97EA721F58B686C37753261F9E4F17E36CBF4DBA8EE76C6
HistoryOct 22, 2019 - 1:40 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Event Streams

2019-10-2213:40:01
www.ibm.com
13

0.002 Low

EPSS

Percentile

57.9%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 8 used by IBM Event Streams. IBM Event Streams has addressed the applicable CVEs.

Vulnerability Details

CVEID: CVE-2019-2762

DESCRIPTION: An unspecified vulnerability related to the Java SE Utilities component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/163826 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2019-2769 DESCRIPTION: An unspecified vulnerability related to the Java SE Utilities component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/163832 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

2019.2.1 or earlier

Remediation/Fixes

Upgrade to IBM Event Streams 2019.4.1 which is available from Passport Advantage.

CPENameOperatorVersion
ibm event streamseqany