There are multiple vulnerabilities in the IBM® SDK, Java Technology Edition that is shipped with IBM WebSphere Application Server. These might affect some configurations of IBM WebSphere Application Server Traditional, IBM WebSphere Application Server Liberty and IBM WebSphere Application Server Hypervisor Edition. These products have addressed the applicable CVEs. If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities is applicable to your code. For a complete list of vulnerabilities, refer to the link for “IBM Java SDK Security Bulletin” located in the References section for more information. HP fixes are on a delayed schedule.
Affected product(s) and affected version(s):
Affected Product(s) | Version(s) |
WebSphere Application Server | 9.0 |
WebSphere Application Server | 8.5 |
WebSphere Application Server Liberty | Continuous delivery |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/pages/node/1289194
The post Security Bulletin: Multiple Vulnerabilities in IBM® Java SDK affect WebSphere Application Server January 2020 CPU appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/3814luu
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.