Lucene search

K
ibmIBMC1794395417F17DE1E2CADE4B2EFBF4B1F926109D610E78629E14E1176BB9952
HistoryJul 24, 2020 - 10:19 p.m.

Security Bulletin: A Vulnerability in IBM Java Runtime Affects IBM Sterling Connect:Direct for Microsoft Windows

2020-07-2422:19:08
www.ibm.com
17

0.0004 Low

EPSS

Percentile

5.1%

Summary

There is a vulnerability in IBM® Runtime Environment Java™ Version 7 and 8 used by IBM Sterling Connect:Direct for Microsoft Windows. IBM Sterling Connect:Direct for Microsoft Windows has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2019-4732
**DESCRIPTION:**IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/172618 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Sterling Connect Direct for Microsoft Windows 4.7
IBM Sterling Connect Direct for Microsoft Windows 4.8
IBM Connect Direct for Microsoft Windows 6.0

For unsupported versions IBM recommends upgrading to a fixed, supported version of the product.

Remediation/Fixes

Affected Product(s) Version(s) APAR Remediation / First Fix
Sterling Connect Direct for Microsoft Windows 4.7 IT32369 Apply 4.7.0.7_iFix008, available on Fix Central
IBM Sterling Connect Direct for Microsoft Windows 4.8 IT32369 Apply 4.8.0.3_iFix009, available on Fix Central
IBM Connect Direct for Microsoft Windows 6.0 IT32369 Apply 6.0.0.4_iFix006, available on Fix Central

Workarounds and Mitigations

None

0.0004 Low

EPSS

Percentile

5.1%

Related for C1794395417F17DE1E2CADE4B2EFBF4B1F926109D610E78629E14E1176BB9952