Lucene search

K
ibmIBMB68450B1EB714756EB8BE1D4F397B1F86638FA9791DF2B06FD41B6BA751DAF04
HistoryFeb 05, 2020 - 12:09 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Rational Application Developer for WebSphere Software

2020-02-0500:09:48
www.ibm.com
12

0.001 Low

EPSS

Percentile

42.9%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Versions 7 and 8 that are used by IBM Rational Application Developer for WebSphere Software. These issues were disclosed as part of the IBM Java SDK updates in April 2017.

Vulnerability Details

CVEID: CVE-2017-3511
DESCRIPTION: An unspecified vulnerability related to the Java SE JCE component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 7.7
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/124890&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

Rational Application Developer 9.6.1 and earlier

Remediation/Fixes

Update the IBM SDK, Java Technology Edition of the product to address this vulnerability:

Product

| VRMF|APAR|Remediation/First Fix
—|—|—|—
Rational Application Developer| 9.5 through 9.6|

PI85999

|

PI85999

|

Workarounds and Mitigations

No known workarounds.