IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect DataPower Gateways
Sep 8, 2018 9:00 am EDT
Categorized: High Severity
Share this post:
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7, 7R1 and 8 used by IBM DataPower Gateway. IBM DataPower Gateway has addressed the applicable CVEs.
CVE(s): CVE-2018-2783 , CVE-2018-2799 , CVE-2018-2798 , CVE-2018-2797 , CVE-2018-2796 , CVE-2018-2795
Affected product(s) and affected version(s):
IBM DataPower Gateway 7.1.0.0 – 7.1.0.22
IBM DataPower Gateway 7.2.0.0 – 7.2.0.20
IBM DataPower Gateway 7.5.0.0 – 7.5.0.16
IBM DataPower Gateway 7.5.1.0 – 7.5.1.15
IBM DataPower Gateway 7.5.2.0 – 7.5.2.15
IBM DataPower Gateway 7.6.0.0 – 7.6.0.8
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10726009
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141939
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141955
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141954
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141953
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141952
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141951
from IBM Product Security Incident Response Team https://ift.tt/2Mbq2N0