IBM Security Bulletin: Multiple security vulnerabilities have been identified in IBM Java Runtime shipped with AppScan Standard (CVE-2018-3180 , CVE-2018-3139)

IBM Java Runtime is shipped as a component of AppScan Standard. Two issues affect AppScan Standard. Information about other security vulnerabilities affecting IBM Java Runtime has been published in another Security Bulletin (https://ibm.co/2GuT1Mp).

CVE(s): CVE-2018-3180, CVE-2018-3139

Affected product(s) and affected version(s):

  • IBM Security AppScan Standard – 9.0.3.0 – 9.0.3.10
  • IBM Security AppScan Standard – 9.0.2.0 – 9.0.2.1
  • IBM Security AppScan Standard – 9.0.1.0 – 9.0.1.1
  • IBM Security AppScan Standard – 9.0.0.0 – 9.0.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10738981
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/151497
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/151455

The post IBM Security Bulletin: Multiple security vulnerabilities have been identified in IBM Java Runtime shipped with AppScan Standard (CVE-2018-3180 , CVE-2018-3139) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ibm.co/2GuT36Z