Lucene search

K
ibmIBMF0FAECCCD03D1BE0A7DAE7C2FB0D3CDF28D07C6EE2EFEFD11446F8EBBBA06084
HistoryJun 15, 2018 - 7:08 a.m.

Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM MQ and IBM MQ Appliance

2018-06-1507:08:12
www.ibm.com
8

0.002 Low

EPSS

Percentile

59.8%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ versions 6, 7 and 8 used by IBM MQ and IBM MQ Appliance. These issues were disclosed as part of the IBM Java SDK updates in July 2017.

Vulnerability Details

If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities are applicable to your code. For a complete list of vulnerabilities please refer to the link for “IBM Java SDK Security Bulletin" located in the “References” section for more information.

CVEID: CVE-2017-10108**
DESCRIPTION:** An unspecified vulnerability related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128869 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2017-10109**
DESCRIPTION:** An unspecified vulnerability related to the Java SE Serialization component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128870 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

CVEID: CVE-2017-10115**
DESCRIPTION:** An unspecified vulnerability related to the Java SE JCE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128876 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVEID: CVE-2017-10116**
DESCRIPTION:** An unspecified vulnerability related to the Java SE Security component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128877 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Affected Products and Versions

IBM MQ 9.0.0.x Long Term Support (LTS)
Maintenance level 9.0.0.1 and earlier

IBM MQ 9.0.x Continuous Delivery Release (CDR)
Continuous delivery update 9.0.3 and earlier

IBM MQ Appliance 9.0.x
Update 9.0.3 and earlier

IBM MQ 8.0
Maintenance levels 8.0.0.7 and earlier

IBM MQ Appliance 8.0
Maintenance levels 8.0.0.7 and earlier

WebSphere MQ 7.5
Maintenance levels 7.5.0.8 and earlier

WebSphere MQ 7.1
Maintenance levels 7.1.0.8 and earlier

Remediation/Fixes

IBM MQ 9.0.0.0
Apply fix pack 9.0.0.2

IBM MQ 9.0.x & IBM MQ Appliance 9.0.x Continuous Delivery Release (CDR)
Upgrade to IBM MQ 9.0.4

IBM MQ V8.0 & IBM MQ Appliance V8.0
Apply fix pack 8.0.0.8

WebSphere MQ 7.5
Apply iFix IT21891

WebSphere MQ 7.1
Apply fix pack 7.1.0.9