IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM WebSphere MQ (CVE-2016-0264, CVE-2016-3426 and CVE-2016-3427)

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 6 and 7 that are used by IBM WebSphere MQ. These issues were disclosed as part of the IBM Java SDK updates in April 2016.



CVE(s): CVE-2016-0264, CVE-2016-3426, CVE-2016-3427


Affected product(s) and affected version(s):

IBM SDK, Java Technology Edition, Version 7R1, provided by IBM WebSphere MQ 8.0.0.4 and earlier on Windows, Linux and AIX
IBM SDK, Java Technology Edition, Version 7, provided by IBM WebSphere MQ 8.0.0.4 and earlier on Solaris and HP-UX
IBM SDK, Java Technology Edition, Version 6, provided by IBM WebSphere MQ 7.5.0.6, IBM WebSphere MQ 7.1.0.7 and earlier on all platforms (except IBM i and z/OS)



Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1NwORmm
X-Force Database: http://ift.tt/1Tg5wqG
X-Force Database: http://ift.tt/1N2N2xe
X-Force Database: http://ift.tt/1N2N48r


from IBM Product Security Incident Response Team http://ift.tt/1NwOI2w