Thursday, September 10, 2020

Security Bulletin: A vulnerability in IBM Java SDK and IBM Java Runtime related to the Kerberos component affect IBM® Db2®. (CVE-2019-2949)

Sep 10, 2020 8:00 pm EDT

Categorized: Medium Severity

Share this post:

In some versions of IBM Java SDK a vulnerability related to the Kerberos component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.

Affected product(s) and affected version(s):

All fix pack levels of IBM Db2 V11.1, and V11.5 editions running on all platforms. IBM Db2 V10.5 is not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6330711



from IBM Product Security Incident Response Team https://ift.tt/3hiUeoV

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.