QID 330080

Date Published: 2021-04-21

QID 330080: IBM AIX Java Multiple Vulnerabilities (java_mar2021_advisory)

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Versions 7, 7.1, 8 used by AIX.

Affected Versions:
AIX 7.1, 7.2

QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L It also checks for interim fixes installed using the command emgr -c or instfix -k The detection posts vulnerable if the installed package version is less than the patched version and interim fixes are also not installed.

Successful attacks of this vulnerability to cause low confidentiality impact, low integrity impact, and high availability impact.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX advisory to obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    IBM AIX URL Logo aix.software.ibm.com/aix/efixes/security/java_mar2021_advisory.asc