Lucene search

K
ibmIBMD01A3C682B872C11438B0E26B61DC1D37C40BF7230C60AD050BCE88B3E4760A8
HistoryJun 15, 2018 - 7:07 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere DataPower XC10 Appliance

2018-06-1507:07:42
www.ibm.com
24

0.005 Low

EPSS

Percentile

76.1%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 6 and 7 that affect the WebSphere DataPower XC10 Appliance. These issues were disclosed as part of the IBM Java SDK updates in Jan 2017.

Vulnerability Details

CVEID: CVE-2016-5548
DESCRIPTION: An unspecified vulnerability related to the Libraries component could allow a remote attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120864 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)

CVEID: CVE-2016-5547 DESCRIPTION: An unspecified vulnerability related to the Libraries component could allow a remote attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120871 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-5552 DESCRIPTION: An unspecified vulnerability related to the Networking component has no confidentiality impact, low integrity impact, and no availability impact.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120872 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

WebSphere DataPower XC10 Appliance Version 2.1
WebSphere DataPower XC10 Appliance Version 2.5

Remediation/Fixes

Product

| VRMF| APAR| Remediation/First Fix
—|—|—|—
WebSphere DataPower XC10 Appliance V2.1 on appliance 9235-92X| 2.1| IT19816| Refer to the Version 2.1 table in Recommended fixes for WebSphere DataPower XC10 Appliance.
WebSphere DataPower XC10 Appliance V2.1 on appliance 7199-92X| 2.1| IT19816| Refer to the** Version 2.1** table in Recommended fixes for WebSphere DataPower XC10 Appliance.
WebSphere DataPower XC10 Appliance V2.5 on appliance 7199-92X| Version 2.5 with SSD drivers **
Important**: See More Information link and follow instructions to determine if you have an old or newer SSD driver on your appliance using the show ssd-version command.| IT19816| Refer to theVersion 2.5 table in Recommended fixes for WebSphere DataPower XC10 Appliance.
WebSphere DataPower XC10 Appliance V2.5 virtual image| 2.5| IT19816| Refer to the** Version 2.5** table in Recommended fixes for WebSphere DataPower XC10 Appliance.

Workarounds and Mitigations

None