IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect DataPower Gateways
Oct 16, 2018 9:01 am EDT
Categorized: High Severity
Share this post:
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7 and 8 used by IBM DataPower Gateways. IBM DataPower Gateways has addressed the applicable CVEs.
CVE(s): CVE-2018-2952, CVE-2018-12539, CVE-2016-0705
Affected product(s) and affected version(s):
- IBM DataPower Gateway: 7.5.0.0 – 7.5.0.17
- IBM DataPower Gateway: 7.5.1.0 – 7.5.1.16
- IBM DataPower Gateway: 7.5.2.0 – 7.5.2.16
- IBM DataPower Gateway: 7.6.0.0 – 7.6.0.8
- IBM DataPower Gateway: 7.7.0.0 – 7.7.1.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10733869
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146815
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148389
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/111140
from IBM Product Security Incident Response Team https://ift.tt/2yiQXSY