Lucene search

K
ibmIBMBA4ED53D3BF345F5D067EA458E9C00169A222A7759D283882B8C2E806FEC9BE7
HistoryJun 18, 2018 - 12:28 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK (or if just using Runtime state IBM Java Runtime) affect IBM Network Advisor (CVE-2015-4748, CVE-2016-2613, CVE-2016-2601, CVE-2016-4749, CVE-2016-2625)

2018-06-1800:28:25
www.ibm.com
10

EPSS

0.039

Percentile

92.0%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition that is used by IBM Network Advisor. These issues were disclosed as part of the IBM Java SDK updates in July 2015.

Vulnerability Details

CVEID: CVE-2015-4748

DESCRIPTION: An unspecified vulnerability related to the Security component has complete confidentiality impact, complete integrity impact, and complete availability impact.

CVSS Base Score: 7.6

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104729 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVEID: CVE-2015-2601

DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.

CVSS Base Score: 5

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104733 for the current score

CVSS Environmental Score*: UndefinedCVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-4749

DESCRIPTION: An unspecified vulnerability related to the JNDI component could allow a remote attacker to cause a denial of service.

CVSS Base Score: 4.3

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104740 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVEID: CVE-2015-2625

DESCRIPTION: An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.

CVSS Base Score: 2.6

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104743 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-1931

DESCRIPTION: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.

CVSS Base Score: 2.1

CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/102967 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-2613

DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.

CVSS Base Score: 5

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104734 for the current score

CVSS Environmental Score*: UndefinedCVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM Network Advisor versions prior to 14.0.2

Remediation/Fixes

Fixes in IBM Network Advisor 14.0.2
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1009621

Workarounds and Mitigations

None