Lucene search

K
ibmIBMF7AE7D9F7AAA61950FB3CCFA12A691E76A633659E46F7DEB436BF225F4D2F6F7
HistoryJul 15, 2021 - 7:03 p.m.

Security Bulletin: IBM Data Replication Affected by Multiple Vulnerabilities in IBM Java SDK

2021-07-1519:03:29
www.ibm.com
7

0.0004 Low

EPSS

Percentile

5.1%

Summary

This bulletin covers common Java SDK vulnerability findings in the IBM Java SDK packaged with this offering.

Vulnerability Details

CVEID:CVE-2019-11771
**DESCRIPTION:**Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by the inclusion of unused RPATHS in AIX builds. An attacker could exploit this vulnerability to inject code and gain elevated privileges on the system.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/163989 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2019-4473
**DESCRIPTION:**Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
CVSS Base score: 8.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/163984 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
InfoSphere Data Replication 11.4.0
InfoSphere Data Replication 11.4
InfoSphere Data Replication 11.3.3

Remediation/Fixes

Update to the latest offering fix pack found here:

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%3FInformation%20Management&product=ibm/Information+Management/IBM+InfoSphere+Data+Replication&release=11.4&platform=All&function=all&source=fc

[https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EInformation%20Management&product=ibm/Information+Management/IBM+InfoSphere+Data+Replication&release=11.3.3.3&platform=All&function=all](<https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EInformation%20Management&product=ibm/Information+Management/IBM+InfoSphere+Data+Replication&release=11.3.3.3&platform=All&function=all>)

Workarounds and Mitigations

None

0.0004 Low

EPSS

Percentile

5.1%

Related for F7AE7D9F7AAA61950FB3CCFA12A691E76A633659E46F7DEB436BF225F4D2F6F7