IBM Security Bulletin: Multiple vulnerabilites in IBM Java Runtime affect IBM Spectrum Protect (Tivoli Storage Manager) Windows and Macintosh Client

There are multiple vulnerabilities in the IBM® Runtime Environment Java™ packaged with the IBM Spectrum Protect (formerly Tivoli Storage Manager) Windows and Macintosh Client. These issues were disclosed as part of the IBM Java SDK updates in July 2017.

CVE(s): CVE-2017-10115, CVE-2017-10116, CVE-2017-10105, CVE-2017-10243

Affected product(s) and affected version(s):

The following versions of the IBM Spectrum Protect (formerly Tivoli Storage Manager) Windows and Macintosh Client are affected:

  • 8.1.0.0 through 8.1.2.x
  • 7.1.0.0 through 7.1.7.x
  • 6.4 and below all levels (6.4 and below are EOS)

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2qiICwQ
X-Force Database: http://ift.tt/2xsr7ZC
X-Force Database: http://ift.tt/2wyaY8O
X-Force Database: http://ift.tt/2x588Yf
X-Force Database: http://ift.tt/2vQ1oZY

The post IBM Security Bulletin: Multiple vulnerabilites in IBM Java Runtime affect IBM Spectrum Protect (Tivoli Storage Manager) Windows and Macintosh Client appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2lNtPWo