IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect DataPower Gateways

Oct 16, 2018 9:01 am EDT

Categorized: High Severity

Share this post:

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 7 and 8 used by IBM DataPower Gateways. IBM DataPower Gateways has addressed the applicable CVEs.

CVE(s): CVE-2018-2952, CVE-2018-12539, CVE-2016-0705

Affected product(s) and affected version(s):

  • IBM DataPower Gateway: 7.5.0.0 – 7.5.0.17
  • IBM DataPower Gateway: 7.5.1.0 – 7.5.1.16
  • IBM DataPower Gateway: 7.5.2.0 – 7.5.2.16
  • IBM DataPower Gateway: 7.6.0.0 – 7.6.0.8
  • IBM DataPower Gateway: 7.7.0.0 – 7.7.1.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10733869
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146815
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148389
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/111140



from IBM Product Security Incident Response Team https://ift.tt/2yiQXSY