IBM Support

Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Cloud Pak System (April2019 updates)

Security Bulletin


Summary

Multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 7 used by the IBM Cloud Pak System formerly known as PureApplication System were disclosed as part of the IBM Java SDK updates in April 2019. IBM Cloud Pak System has addressed the vulnerabilities.

Vulnerability Details

CVEID: CVE-2019-2684
DESCRIPTION: An unspecified vulnerability in Java SE related to the Java SE, Java SE Embedded RMI component could allow an unauthenticated attacker to cause no confidentiality impact, high integrity impact, and no availability impact.
CVSS Base Score: 5.9
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/159776 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)

CVEID: CVE-2019-2602
DESCRIPTION: An unspecified vulnerability in Java SE related to the Java SE, Java SE Embedded Libraries component could allow an unauthenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/159698 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM Cloud Pak  System V2.2.3-V2.2.4
IBM Cloud Pak  System V2.3.0.0

Remediation/Fixes

For all unsupported  version/releases/platforms,  IBM Cloud Pak System/Software/Sotware Suite and Service v2.2.3 and v2.2.4 ,  that are end of support , hardware appliance Machine Type Cloud Pak System W1700 and W1500 end of life, IBM recommends to upgrade to supported Cloud Pak System version/release/platform.

IBM Cloud Pak System recommends to upgrade to Cloud Pak System fixed release. Contact IBM Cloud Pak support for assistance.

For IBM Cloud Pak  System V2.3.0

Upgrade the IBM CloudPak System to the following fixed release:

  • IBM Cloud Pak  System V2.3.0.1


Information on upgrading can be found here: http://www.ibm.com/support/docview.wss?uid=ibm10887959

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

September 27, 2019: Original document published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

CVEID: CVE-2019-2684, CVE-2019-2602

Notice : To be updated on 30 Sept with information about 2.2.

The W1500 and W1700 Systems  are no longer in full support for  Cloud Pak  System v2.2.3 and v2.2.4.

[{"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SSM8NY","label":"PureApplication System"},"Component":"Security","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"2.2.6.0;2.2.5.3;2.2.5.2;2.2.5.1;2.2.5.0;2.2.4.0;2.2.3.2;2.2.3.1;2.2.3.0","Edition":"All Editions","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
03 October 2019

UID

ibm11074396