Security Bulletin
Summary
Security vulnerabilities have been identified in IBM® Runtime Environment Java™ Technology Edition that is used by Watson Explorer, Watson Content Analytics and Watson Explorer Content Analytics Studio.
Vulnerability Details
CVEID: CVE-2017-10115
DESCRIPTION: An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit JCE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128876 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CVEID: CVE-2017-10116
DESCRIPTION: An unspecified vulnerability in Oracle Java SE related to the Java SE, Java SE Embedded, JRockit Security component could allow an unauthenticated attacker to take control of the system.
CVSS Base Score: 8.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/128877 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
Affected Products and Versions
These vulnerabilities apply to the following products and versions:
|
Affected Product | Affected Versions | Applicable Vulnerabilities |
| Watson Explorer Foundational Components | 11.0.0.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | CVE-2017-10115 CVE-2017-10116 |
| Watson Explorer Foundational Components | 10.0.0.0 - 10.0.0.4 | CVE-2017-10115 CVE-2017-10116 |
| Watson Explorer Foundational Components | 9.0.0.0 - 9.0.0.8 | CVE-2017-10115 CVE-2017-10116 |
| Watson Explorer Foundational Components | 8.2 - 8.2-6 | CVE-2017-10115 CVE-2017-10116 |
| IBM Watson Explorer Foundational Components Annotation Administration Console | 11.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | CVE-2017-10115 CVE-2017-10116 |
| IBM Watson Explorer Foundational Components Annotation Administration Console | 10.0 - 10.0.0.4 | CVE-2017-10115 CVE-2017-10116 |
| Watson Explorer Analytical Components | 11.0.0.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | CVE-2017-10115 CVE-2017-10116 |
| Watson Explorer Analytical Components | 10.0.00 - 10.0.0.4 | CVE-2017-10115 CVE-2017-10116 |
| IBM Watson Content Analytics | 3.5.0.0 - 3.5.0.4 | CVE-2017-10115 CVE-2017-10116 |
| IBM Watson Explorer Content Analytics Studio | 11.0.0.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | CVE-2017-10115 CVE-2017-10116 |
Remediation/Fixes
Follow these steps to upgrade to the required version of IBM Java Runtime.
The table reflects product names at the time the specified versions were released. To use the links to Fix Central in this table, you must first log in to the IBM Support Fix Central site at http://www.ibm.com/support/fixcentral/.
| Affected Product | Affected Versions | Required IBM Java Runtime | How to acquire and apply the fix |
|---|---|---|---|
| IBM Watson Explorer Foundational Components | 11.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | JVM 8 SR4 FP10 or later | Upgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures. |
| IBM Watson Explorer Foundational Components | 10.0 - 10.0.0.4 | JVM 8 SR4 FP10 or later |
|
| IBM Watson Explorer | 9.0 - 9.0.0.8 | JVM 7.1 SR4 FP10 or later |
|
| IBM InfoSphere Data Explorer | 8.2 - 8.2-6 | JVM 7.1 SR4 FP10 or later |
|
| IBM Watson Explorer Foundational Components Annotation Administration Console | 11.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | JVM 8 SR4 FP10 or later | Upgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures. |
| IBM Watson Explorer Foundational Components Annotation Administration Console | 10.0 - 10.0.0.4 | JVM 7 SR10 FP10 or later |
|
| IBM Watson Explorer Analytical Components | 11.0 - 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 | JVM 8 SR4 FP10 or later | Upgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures. |
| IBM Watson Explorer Analytical Components | 10.0 - 10.0.0.2 | JVM 7 SR10 FP10 or later |
|
| IBM Watson Content Analytics | 3.5 - 3.5.0.4 | JVM 7 SR10 FP10 or later |
|
| IBM Watson Explorer Content Analytics Studio | 11.0 - 11.0.0.3, 11.0.1 | JVM 8 SR4 FP10 or later | If you have not already installed, upgrade to Version 11.0.2.2.
|
| IBM Watson Explorer Content Analytics Studio | 11.0.2, 11.0.2.1 | JVM 8 SR4 FP10 or later | Upgrade to Watson Explorer Analytical Components Version 11.0.2.2. For information about this version, and links to the software and release notes, see the download document. For information about upgrading, see the upgrade procedures. |
Get Notified about Future Security Bulletins
References
Change History
4 Dec 2017 Updated to suggest upgrading to 11.0.2.2 for Version 11.
17 Nov 2017 Updated Version 11 entries
6 Nov 2017 Initially published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Internal Use Only
4 Dec 2017 : Updated
Nov.17.2017 : Got deviation for 11.0.2.1 but some PMRs were coming from the customer, so tested with 8.0.4.11 and republished with information for V11.0.2.1 FC/AC/CAStudio.
Oct.24.2017 : initial draft is created, but V11 will be fixed in next Fix Pack, targeting Dec.2017. Need deviation on this.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg22009912