Lucene search

K
ibmIBMFA5F012428FA51EA7AFE9FB0E2171B2CD67D77D2E18E2941289FA0D3B22D0385
HistoryMay 11, 2021 - 9:47 a.m.

Security Bulletin: Vulnerabilities in IBM Java Runtime affect IBM Netcool Agile Service Manager

2021-05-1109:47:21
www.ibm.com
22
ibm java runtime
netcool agile service manager
vulnerabilities
cve-2020-14803
cve-2020-27221
update

EPSS

0.004

Percentile

75.0%

Summary

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 8 used by IBM Netcool Agile Service Manager. IBM Netcool Agile Service Manager has addressed the applicable CVEs. These issues were disclosed as part of the IBM Java SDK updates in January 2021.

Vulnerability Details

CVEID:CVE-2020-14803
**DESCRIPTION:**An unspecified vulnerability in Java SE could allow an unauthenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190121 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
Netcool Operations Insight 1.6 Netcool Operations Insight 1.6
IBM Netcool Agile Service Manager 1.1

Remediation/Fixes

Update to IBM Netcool Agile Service Manager 1.1.10 (Netcool Operations Insight 1.6.3)

On OCP

Download IBM Netcool Operations Insight V1.6.3 on Red Hat OpenShift

Workarounds and Mitigations

None