Lucene search

K
ibmIBME613835736670FB1968C3C6B79998927CD473DD1455F2D9C369EB4D23D4A42FB
HistoryJun 17, 2018 - 12:12 p.m.

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect eDiscovery Analyzer (CVE-2015-2613, CVE-2015-2601, CVE-2015-2625, CVE-2015-1931)

2018-06-1712:12:00
www.ibm.com
6

EPSS

0.008

Percentile

81.6%

Summary

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition that is used by eDiscovery Analyzer. These issues were disclosed as part of the IBM Java SDK updates in July 2015.

Vulnerability Details

**
CVEID:**CVE-2015-2613 DESCRIPTION: An unspecified vulnerability and Java SE Embedded related to the JCE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104734 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-2601 DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104733 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-2625 DESCRIPTION: An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/104743 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N)

CVEID: CVE-2015-1931 DESCRIPTION: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
CVSS Base Score: 2.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/102967 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM eDiscovery Analyzer Version 2.2
IBM eDiscovery Analyzer Version 2.2.1
IBM eDiscovery Analyzer Version 2.2.2

Remediation/Fixes

For version 2.2.2.2, apply the available fix as soon as practical. Contact IBM Support if you are using versions 2.2 or 2.2.1.

Go to Fix Central for eDiscovery Analyzer, and install the fix applicable to the version that you have installed and your platform.

2.2.2.2 Interim Fix 2

EPSS

0.008

Percentile

81.6%