Dec 9, 2019 7:00 pm EST
Categorized: Medium Severity
Share this post:
There are multiple vulnerabilities in the IBM® SDK Java™ Technology Edition that is shipped with IBM WebSphere Application Server. These might affect some configurations of IBM WebSphere Application Server Traditional, IBM WebSphere Application Server Liberty and IBM WebSphere Application Server Hypervisor Edition. These products have addressed the applicable CVEs. If you run your own Java code using the IBM Java Runtime delivered with this product, you should evaluate your code to determine whether the complete list of vulnerabilities is applicable to your code. For a complete list of vulnerabilities, refer to the link for “IBM Java SDK Security Bulletin” located in the References section for more information. HP fixes are on a delayed schedule.
Affected product(s) and affected version(s):
IBM SDK, Java Technology Editions used with WebSphere Application Server Liberty
IBM SDK, Java Technology Editions used with IBM WebSphere Application Server Traditional Version 188.8.131.52 through 184.108.40.206, 220.127.116.11 through 18.104.22.168.
IBM SDK, Java Technology Editions shipped in Application Client for IBM WebSphere Application Server Version 22.214.171.124 through 126.96.36.199, 188.8.131.52 through 184.108.40.206.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/pages/node/1126887