Lucene search

K
ibmIBMCF6040F8CD74D777BAE53AAEAA4A30BA7F1467798079B52933C2FA2D576E4A3A
HistoryJan 12, 2023 - 11:45 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java - OpenJ9 affect IBM Tivoli System Automation for Multiplatforms (CVE-2021-41041)

2023-01-1211:45:29
www.ibm.com
16
ibm java
eclipse-openj9
ibm tivoli system automation
multiplatforms
cve-2021-41041
vulnerabilities
remediation
fixes

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

33.3%

Summary

There are multiple vulnerabilities in IBM Java Eclipse-OpenJ9 used by 4.1.0.4 to 4.1.0.7 of IBM Tivoli System Automation for Multiplatforms.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli System Automation for Multiplatforms 4.1

Remediation/Fixes

Remediation/Fixes:
The recommended solution is to apply the corresponding fix to IBM Tivoli System Automation for Multiplatforms. To select the fix you need to apply in your environment, click on ‘Download link’ in the table below.

  • If you are running IBM Tivoli System Automation for Multiplatforms 4.1.0.4, please apply interim fix “4.1.0.4-TIV-ITSAMP-<OS>-IF0017” where <OS> represents the operating system for which you want to install the interim fix of this product version. You can apply this interim fix on top of 4.1.0.4.
  • If you are running IBM Tivoli System Automation for Multiplatforms 4.1.0.5, please apply interim fix “4.1.0.5-TIV-ITSAMP-<OS>-IF0011” where <OS> represents the operating system for which you want to install the interim fix of this product version. You can apply this interim fix on top of 4.1.0.5.
  • If you are running IBM Tivoli System Automation for Multiplatforms 4.1.0.6, please apply interim fix “4.1.0.6-TIV-ITSAMP-<OS>-IF0006” where <OS> represents the operating system for which you want to install the interim fix of this product version. You can apply this interim fix on top of 4.1.0.6.
  • If you are running IBM Tivoli System Automation for Multiplatforms 4.1.0.7, please apply interim fix “4.1.0.7-TIV-ITSAMP-<OS>-IF0004” where <OS> represents the operating system for which you want to install the interim fix of this product version. You can apply this interim fix on top of 4.1.0.7.Product|VRMF|APAR
    —|—|—
    IBM Tivoli System Automation for Multiplatforms| 4.1| Download Link

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmtxseries_for_multiplatformsMatch4.1
VendorProductVersionCPE
ibmtxseries_for_multiplatforms4.1cpe:2.3:a:ibm:txseries_for_multiplatforms:4.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

33.3%

Related for CF6040F8CD74D777BAE53AAEAA4A30BA7F1467798079B52933C2FA2D576E4A3A