IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM MQ Internet Pass Thru

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7.0.10.5 used by IBM MQ Internet Pass Thru. These issues were disclosed as part of the IBM Java SDK updates in July 2017.

CVE(s): CVE-2017-10108, CVE-2017-10109, CVE-2017-10115, CVE-2017-10116

Affected product(s) and affected version(s):

IBM SDK, Java Technology Edition, Version 7 Service Refresh 10 Fix Pack 5 and earlier releases provided by WebSphere MQIPT 2.1 on all platforms.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2kdm7qI
X-Force Database: http://ift.tt/2vff6pW
X-Force Database: http://ift.tt/2vEvu3j
X-Force Database: http://ift.tt/2xsr7ZC
X-Force Database: http://ift.tt/2wyaY8O

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM MQ Internet Pass Thru appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2Bx9J8O