Security Bulletin
Summary
WebSphere Message Broker 及び IBM Integration Busで使用される下記バージョンのRuntime Environment Java™ Technology Editionには複数の脆弱性が存在します。
-WebSphere Message Broker で使用されるIBM® Runtime Environment Java™ Technology Editionの Version 6 Service Refresh 16 Fix Pack 41 以前のリリース
-WebSphere Message Broker 及び IBM Integration Busで使用されるIBM® Runtime Environment Java™ Technology Edition のVersion 7 Service Refresh 10 Fix Pack 1以前のリリース
-IBM Integration Busで使用される IBM® Runtime Environment Java™ Technology Edition Version の 7R1 Service Refresh 4 Fix Pack 1
これらの脆弱性への対応として2017年4月にIBM Java SDK の修正モジュールが提供されました。
最新の情報は下記の文書(英語)をご参照ください。
Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere Message Broker and IBM Integration Bus
http://www-01.ibm.com/support/docview.wss?uid=swg22005345
Vulnerability Details
製品に付属のIBM Java Runtimeを使用して独自のJavaコードを実装している場合は、コードを評価し脆弱性の影響有無について判断する必要があります。 脆弱性の完全なリストについてはIBM Java SDK Security Bulletin を参照してください。
CVEID: CVE-2017-3511
概要:Java SE、Java SE Embedded、JRockit JCEコンポーネントに関連するOracle Java SEの不特定の脆弱性により、認証されていない攻撃者がシステムを制御できる可能性があります。
CVSS Base Score: 7.7
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/124890 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
CVEID: CVE-2017-1289
概要: XMLデータの処理時に脆弱なXML External Entity Injection (XXE)エラーを引き起こされる可能性のある脆弱性が存在します。 リモートの攻撃者はこの脆弱性を悪用して、機密性の高い情報を公開したり、メモリリソースを消費する可能性があります。
CVSS Base Score: 8.2
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/125150 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)
CVEID: CVE-2016-9840
概要:zlibのinftrees.cの脆弱性により、リモートの攻撃者は被害者に不適切なポインタ演算をさせることでサービス妨害を引き起こす可能性があります。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120508 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
CVEID: CVE-2016-9841
概要:zlibのinffast.cの脆弱性により、リモートの攻撃者は被害者に不適切なポインタ演算をさせることでサービス妨害を引き起こす可能性があります。
CVSS Base Score: 3.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120509 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
CVEID: CVE-2016-9842
概要:zlib の inflate.c の inflateMark 関数の脆弱性により、リモートの攻撃者は、負の整数の左シフトに関する問題によってサービス妨害を引き起こす可能性がございます。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120510 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
CVEID: CVE-2016-9843
概要:zlib の crc32.c の crc32_big 関数の脆弱性により、リモートの攻撃者はビッグエンディアンの CRC 計算に関する問題によってサービス妨害を引き起こす可能性がございます。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120511 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Affected Products and Versions
次の製品・バージョンで影響があります。
IBM Integration Bus V10.0.0.0- 10.0.0.8
IBM Integration Bus V9.0.0.0- 9.0.0.7
WebSphere Message Broker V8.0.0.0 - 8.0.0.8
Remediation/Fixes
|
Product | VRMF | APAR | Remediation/Fix |
| IBM Integration Bus | V10.0.0.0- 10.0.0.8 | IT20410 | このAPAR は fix pack 10.0.0.9 に含まれます (HPを除く全てのプラットフォーム) |
| IBM Integration Bus | V9.0.0.0- 9.0.0.7 | IT20410 | このAPAR は fix pack 9.0.0.8 に含まれます (HPを除く全てのプラットフォーム) |
| WebSphere Message Broker | V8.0.0.0 - 8.0.0.8 | IT20410 | このAPAR は fix pack 8.0.0.9 に含まれます (HPを除く全てのプラットフォーム) |
Get Notified about Future Security Bulletins
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
23 March 2020
UID
swg22005576