Lucene search

K
ibmIBMC0BAD1C431F2B4E739BB3060AD777A585B1895B14110ACB28FAE581619333FE5
HistoryDec 16, 2020 - 5:50 p.m.

Security Bulletin: Java vulnerabilities affect IBM Watson Text to Speech and Speech to Text (IBM Watson Speech Services for Cloud Pak for Data 1.2)

2020-12-1617:50:33
www.ibm.com
17
ibm watson
text to speech
speech to text
cloud pak for data
cve-2020-2601
oracle java se
cvss
vulnerabilities
remediation
java version

EPSS

0.001

Percentile

34.4%

Summary

Java vulnerabilities, listed below, affect IBM Watson Text to Speech and Speech to Text (IBM Watson Speech Services for Cloud Pak for Data 1.2)

Vulnerability Details

CVEID:CVE-2020-2601
**DESCRIPTION:**An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded Security component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174548 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Watson Speech Services for Cloud Pak for Data 1.2

Remediation/Fixes

Download and install the newest deployment of IBM Watson Speech Services for Cloud Pak for Data 1.2 to your cluster. This deployment includes Java version: 1.8.0_sr6fp16 (8.0.6.16), or higher, which contains the latest fixes for the issues described above.

Workarounds and Mitigations

None