Download
Abstract
This document lists the fixes contained in IBM PureApplication System 2.0.0.1 Interim Fix 6.
Download Description
To download the interim fix, go to the PureApplication System product page on Fix Central.
Version 2.0.0.1 Interim Fix 6 includes fixes for these security vulnerabilities:
- CVEID: CVE-2015-2613
- DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
- DESCRIPTION: An unspecified vulnerability related to the JCE component could allow a remote attacker to obtain sensitive information.
- DESCRIPTION: An unspecified vulnerability related to the JSSE component could allow a remote attacker to obtain sensitive information.
- DESCRIPTION: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system.
- DESCRIPTION: OpenSSL is vulnerable to a denial of service, caused by an error when processing an ECParameters structure over a specially crafted binary polynomial field. A remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.
Web Application Pattern type version 2.0.2.5, which you can download from Fix Central, contains a fix for this security vulnerability:
- CVEID: CVE-2015-7450
- DESCRIPTION: Apache Commons Collections could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of data with Java InvokerTransformer class. By sending specially crafted data, an attacker could exploit this vulnerability to execute arbitrary Java code on the system.
The following table contains the Authorized Program Analysis Reports (APARs) included in this release.
If an integrated pattern or component is not listed, there were no fixes for that pattern or component in this version.
System APARs
APAR | Abstract |
| "Failed to delete snapshot" error prevents a virtual system delete operation | |
| System console becomes unavailable due to an internal network connectivity interruption |
Off
[{"Product":{"code":"SSM8NY","label":"PureApplication System"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF002","label":"AIX"}],"Version":"2.0.0.1","Edition":"","Line of Business":{"code":"","label":""}}]
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg24041239