IBM Support

IBM PureApplication System Version 2.0.0.1 Interim Fix 6

Download


Abstract

This document lists the fixes contained in IBM PureApplication System 2.0.0.1 Interim Fix 6.

Download Description

To download the interim fix, go to the PureApplication System product page on Fix Central.

Version 2.0.0.1 Interim Fix 6 includes fixes for these security vulnerabilities:

    CVEID: CVE-2015-2613
      DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
    CVEID: CVE-2015-2601
      DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
    CVEID: CVE-2015-2625
      DESCRIPTION: An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.
    CVEID: CVE-2015-1931
      DESCRIPTION: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
    CVEID: CVE-2015-1788
      DESCRIPTION: OpenSSL is vulnerable to a denial of service, caused by an error when processing an ECParameters structure over a specially crafted binary polynomial field. A remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.

Web Application Pattern type version 2.0.2.5, which you can download from Fix Central, contains a fix for this security vulnerability:
    CVEID: CVE-2015-7450
      DESCRIPTION: Apache Commons Collections could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of data with Java InvokerTransformer class. By sending specially crafted data, an attacker could exploit this vulnerability to execute arbitrary Java code on the system.

The following table contains the Authorized Program Analysis Reports (APARs) included in this release.

If an integrated pattern or component is not listed, there were no fixes for that pattern or component in this version.

System APARs

APAR
Abstract
"Failed to delete snapshot" error prevents a virtual system delete operation
System console becomes unavailable due to an internal network connectivity interruption

Off
[{"Product":{"code":"SSM8NY","label":"PureApplication System"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF002","label":"AIX"}],"Version":"2.0.0.1","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
15 June 2018

UID

swg24041239