Lucene search

K
ibmIBMBB18FD7AA3642CF81192225A8B6D5255ED8F5BA8C4F9521ED9F05F5328585763
HistoryMay 18, 2020 - 11:58 a.m.

Security Bulletin: IBM MQ is affected by multiple vulnerabilities in IBM Java Runtime

2020-05-1811:58:56
www.ibm.com
18

EPSS

0.001

Percentile

38.0%

Summary

There are multiple vulnerabilities in IBM Runtime Environment Java Version 7 and 8 used by IBM MQ. IBM MQ have addressed the applicable CVEs. These issues were disclosed as part of the IBM Java SDK updates in October 2019.

Vulnerability Details

CVEID:CVE-2019-2964
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Concurrency component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169270 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2019-2978
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Networking component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169284 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID:CVE-2019-2983
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169289 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.1 LTS
IBM MQ 9.0 LTS
IBM MQ 8.0
IBM MQ 9.1 CD

Remediation/Fixes

IBM MQ 9.1 Long Term Support (LTS)
Apply Fix Pack 9.1.0.5

IBM MQ 9.1 Continuous Delivery Release (CDR)
Apply Continuous Delivery Release Update 9.1.5

IBM MQ 9.0.0.x Long Term Support (LTS)
Apply Fix Pack 9.0.0.9

IBM MQ V8.0
Apply Fix Pack 8.0.0.14

Workarounds and Mitigations

None