IBM Support

IBM Java Runtimeの複数の脆弱性がIBM Integration Bus 及び Websphere Message Brokerに与える影響について

Created by Tadakatsu Kaiho on
Published URL:
https://www.ibm.com/support/pages/node/564071
564071

Security Bulletin


Summary

WebSphere Message Broker 及び IBM Integration Busで使用される下記バージョンのRuntime Environment Java™ Technology Editionには複数の脆弱性が存在します。

-WebSphere Message Broker で使用されるIBM® Runtime Environment Java™ Technology Editionの Version 6 Service Refresh 16 Fix Pack 41 以前のリリース
-WebSphere Message Broker 及び IBM Integration Busで使用されるIBM® Runtime Environment Java™ Technology Edition のVersion 7 Service Refresh 10 Fix Pack 1以前のリリース
-IBM Integration Busで使用される IBM® Runtime Environment Java™ Technology Edition Version の 7R1 Service Refresh 4 Fix Pack 1

これらの脆弱性への対応として2017年4月にIBM Java SDK の修正モジュールが提供されました。

最新の情報は下記の文書(英語)をご参照ください。
Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere Message Broker and IBM Integration Bus
http://www-01.ibm.com/support/docview.wss?uid=swg22005345

Vulnerability Details


製品に付属のIBM Java Runtimeを使用して独自のJavaコードを実装している場合は、コードを評価し脆弱性の影響有無について判断する必要があります。 脆弱性の完全なリストについてはIBM Java SDK Security Bulletin を参照してください。


CVEID: CVE-2017-3511
概要:Java SE、Java SE Embedded、JRockit JCEコンポーネントに関連するOracle Java SEの不特定の脆弱性により、認証されていない攻撃者がシステムを制御できる可能性があります。
CVSS Base Score: 7.7
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/124890 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

CVEID: CVE-2017-1289
概要: XMLデータの処理時に脆弱なXML External Entity Injection (XXE)エラーを引き起こされる可能性のある脆弱性が存在します。 リモートの攻撃者はこの脆弱性を悪用して、機密性の高い情報を公開したり、メモリリソースを消費する可能性があります。
CVSS Base Score: 8.2
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/125150 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)

CVEID: CVE-2016-9840
概要:zlibのinftrees.cの脆弱性により、リモートの攻撃者は被害者に不適切なポインタ演算をさせることでサービス妨害を引き起こす可能性があります。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120508 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-9841
概要:zlibのinffast.cの脆弱性により、リモートの攻撃者は被害者に不適切なポインタ演算をさせることでサービス妨害を引き起こす可能性があります。
CVSS Base Score: 3.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/120509 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-9842
概要:zlib の inflate.c の inflateMark 関数の脆弱性により、リモートの攻撃者は、負の整数の左シフトに関する問題によってサービス妨害を引き起こす可能性がございます。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120510 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

CVEID: CVE-2016-9843
概要:zlib の crc32.c の crc32_big 関数の脆弱性により、リモートの攻撃者はビッグエンディアンの CRC 計算に関する問題によってサービス妨害を引き起こす可能性がございます。
CVSS Base Score: 3.3
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/120511 を参照してください。
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)

Affected Products and Versions

次の製品・バージョンで影響があります。

IBM Integration Bus V10.0.0.0- 10.0.0.8

IBM Integration Bus V9.0.0.0- 9.0.0.7

WebSphere Message Broker V8.0.0.0 - 8.0.0.8

Remediation/Fixes

Product

VRMFAPARRemediation/Fix
IBM Integration BusV10.0.0.0- 10.0.0.8IT20410 このAPAR は fix pack 10.0.0.9 に含まれます (HPを除く全てのプラットフォーム)

http://www-01.ibm.com/support/docview.wss?uid=swg24043686

IBM Integration BusV9.0.0.0- 9.0.0.7IT20410 このAPAR は fix pack 9.0.0.8 に含まれます (HPを除く全てのプラットフォーム)

http://www-01.ibm.com/support/docview.wss?uid=swg24043751

WebSphere Message BrokerV8.0.0.0 - 8.0.0.8IT20410 このAPAR は fix pack 8.0.0.9 に含まれます (HPを除く全てのプラットフォーム)

https://www.ibm.com/support/docview.wss?uid=swg24043806

Get Notified about Future Security Bulletins

References

Off

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSNQK6","label":"IBM Integration Bus"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Not Applicable","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"10.0;9.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
23 March 2020

UID

swg22005576