There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition and IBM® Runtime Environment Java™ Version that is provided with IBM WebSphere Application Server. These issues were disclosed as part of the IBM Java SDK updates for Oct 2017 CPU . These issues were addressed by IBM WebSphere Application Server shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise.
CVE(s): CVE-2017-10345, CVE-2017-10295, CVE-2017-10281, CVE-2017-10350, CVE-2017-10347, CVE-2017-10349, CVE-2017-10348, CVE-2017-10357, CVE-2017-10355, CVE-2017-10293, CVE-2017-10356, CVE-2017-10309, CVE-2017-10388, CVE-2017-10285, CVE-2017-10346, CVE-2016-10165
Affected product(s) and affected version(s):
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg2C1000370
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133774
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133729
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133720
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133779
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133776
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133778
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133777
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133786
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133784
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133727
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133785
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133738
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133813
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133723
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/133775
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/127028
The post IBM Security Bulletin: Security Bulletin: IBM Cloud Orchestrator and Cloud Orchestrator Enterprise update of IBM® SDK Java™ Technology Edition and IBM® Runtime Environment Java™ appeared first on IBM PSIRT Blog.
Principal Product and Version(s) | Affected Supporting Product and Version |
IBM Cloud Orchestrator and Cloud Orchestrator Enterprise V2.5, V2.5.0.1, V2.5.0.2, V2.5.0.4, V2.5.0.5 | WebSphere Application Server V8.5.5 – V8.5.5.12 |
IBM Cloud Orchestrator and Cloud Orchestrator Enterprise V2.4, V2.4.0.1, V2.4.0.2, V2.4.0.4, V2.4.0.5 | WebSphere Application Server V8.5.0.1 through V8.5.5.12 |
IBM Cloud Orchestrator and Cloud Orchestrator Enterprise V2.3, V2.3.0.1 | IBM WebSphere Application Server V8.0.0.1 to V8.0.0.11 |
from IBM Product Security Incident Response Team https://ift.tt/2LBujtX
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.