Lucene search

K
ibmIBMD95EDF686012146F9A7732CD200C406F0E6F482FDC403311570CBF33C3E29E71
HistoryJun 16, 2018 - 9:31 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect Security Directory Integrator

2018-06-1621:31:52
www.ibm.com
21

EPSS

0.008

Percentile

81.6%

Summary

There are multiple vulnerabilities in IBM Runtime Environment Java Technology Edition, Version 5.0 , Version 6.0 and Version 7.0 that is used by Security Directory Integrator. Some of these issues were disclosed as part of the IBM Java SDK updates in July 2015.

Vulnerability Details

CVEID: CVE-2015-2613**
DESCRIPTION:** An unspecified vulnerability and Java SE Embedded related to the JCE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104734 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-2601**
DESCRIPTION:** An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104733 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-2625**
DESCRIPTION:** An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104743 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-1931**
DESCRIPTION:** IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
CVSS Base Score: 2.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/102967 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM Tivoli Directory Integrator 6.1.1
IBM Tivoli Directory Integrator 7.0.0
IBM Tivoli Directory Integrator 7.1.0
IBM Tivoli Directory Integrator 7.1.1
IBM Security Directory Integrator 7.2.0

Remediation/Fixes

Affected Products and Versions

| Fix availability
—|—
TDI 6.1.1| 7.0.0-TIV-TDI-LA0025
TDI 7.0| 7.0.0-TIV-TDI-LA0025
TDI 7.1| 7.1.1-TIV-TDI-LA0028
TDI 7.1.1| 7.1.1-TIV-TDI-LA0028
SDI 7.2| 7.2.0-ISS-SDI-LA0009

You should verify applying this configuration change does not cause any compatibility issues. If you change the default setting after applying the fix, you will expose yourself to the attack described above. IBM recommends that you review your entire environment to identify other areas where you have enabled the Diffie-Hellman key-exchange protocol used in TLS and take appropriate mitigation and remediation actions.

EPSS

0.008

Percentile

81.6%