IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Planning Analytics.
Oct 16, 2018 9:00 am EDT
Categorized: High Severity
Share this post:
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 7 used by IBM Planning Analytics. These issues were disclosed as part of the IBM Java SDK updates in January 2018, April 2018 and July 2018. As of version 2.0.6, IBM Planning Analytics is no longer compatible with IBM® Runtime Environment Java™ Version 7. IBM Planning Analytics 2.0.6 (Windows) will install IBM® Runtime Environment Java™ Version 8. If you run your own Java code , you must upgrade to the latest version of IBM® Runtime Environment Java™ Version 8 that resolves these vulnerabilities. Refer to the IBM Java SDK Security Bulletin (July 2018) in the
CVE(s): CVE-2018-2602, CVE-2018-2603, CVE-2018-2634, CVE-2018-2637, CVE-2018-2633, CVE-2018-2795, CVE-2018-2796, CVE-2018-2797, CVE-2018-2783, CVE-2018-2790, CVE-2017-3736, CVE-2017-3732, CVE-2016-0705, CVE-2018-1517, CVE-2018-1656, CVE-2018-2964, CVE-2018-2973, CVE-2018-2952, CVE-2018-2940, CVE-2018-12539
Affected product(s) and affected version(s):
Planning Analytics 2.0
Planning Analytics 2.0.1
Planning Analytics 2.0.2
Planning Analytics 2.0.3
Planning Analytics 2.0.4
Planning Analytics 2.0.5
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10732896
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137854
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137855
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137886
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137889
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137885
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141951
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141952
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141953
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141939
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141946
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134397
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/121313
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/111140
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/141681
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144882
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146827
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146835
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146815
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/146803
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148389
from IBM Product Security Incident Response Team https://ift.tt/2yiQTmc