IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect DataPower Gateways

Sep 8, 2018 9:00 am EDT

Categorized: High Severity

Share this post:

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7, 7R1 and 8 used by IBM DataPower Gateway. IBM DataPower Gateway has addressed the applicable CVEs.

CVE(s): CVE-2018-2783 , CVE-2018-2799 , CVE-2018-2798 , CVE-2018-2797 , CVE-2018-2796 , CVE-2018-2795

Affected product(s) and affected version(s):

IBM DataPower Gateway 7.1.0.0 – 7.1.0.22

IBM DataPower Gateway 7.2.0.0 – 7.2.0.20

IBM DataPower Gateway 7.5.0.0 – 7.5.0.16

IBM DataPower Gateway 7.5.1.0 – 7.5.1.15

IBM DataPower Gateway 7.5.2.0 – 7.5.2.15

IBM DataPower Gateway 7.6.0.0 – 7.6.0.8

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10726009
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141939
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141955
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141954
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141953
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141952
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141951



from IBM Product Security Incident Response Team https://ift.tt/2Mbq2N0