Lucene search

K
ibmIBMDC350D08CD85CA0672A85E567E3BB2AFC3354EAAF4984AAF4B655C7108D3BF9A
HistoryApr 09, 2021 - 11:41 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect TXSeries for Multiplatforms

2021-04-0911:41:57
www.ibm.com
20
ibm txseries
multiplatforms
java runtime
vulnerabilities
cve-2020-14803
cve-2020-27221
eclipse openj9
stack-based buffer overflow
utf-8
remediation
fix central link

EPSS

0.004

Percentile

75.0%

Summary

TXSeries for Multiplatforms has addressed the following vulnerabilities reported by IBM® Runtime Environment Java™

Vulnerability Details

CVEID:CVE-2020-14803
**DESCRIPTION:**An unspecified vulnerability in Java SE could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190121 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM TXSeries for Multiplatforms 8.2.0.0-8.2.0.2
IBM TXSeries for Multiplatforms 9.1.0.0-9.1.0.1

Remediation/Fixes

Product Version Defect Remediation / First Fix
IBM TXSeries for Multiplatforms v9.1

9.1.0.0

9.1.0.1

| 126860| Fix Central Link
IBM TXSeries for Multiplatforms v8.2|

8.2.0.0

8.2.0.1

8.2.0.2

| 126860| Fix Central Link

Workarounds and Mitigations

None