QID 330088

Date Published: 2021-10-28

QID 330088: IBM AIX Java Multiple Vulnerabilities (java_sep2021_advisory)

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Versions 7, 7.1, 8 used by AIX.

Affected Versions:
AIX 7.1, 7.2

QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L It also checks for interim fixes installed using the command emgr -c or instfix -k The detection posts vulnerable if the installed package version is less than the patched version and interim fixes are also not installed.

Successful attacks of this vulnerability to cause low confidentiality impact, low integrity impact, and high availability impact.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX advisory or visit IBM advisory to obtain more information.

    CVEs related to QID 330088

    Software Advisories
    Advisory ID Software Component Link
    java_sep2021_advisory URL Logo aix.software.ibm.com/aix/efixes/security/java_sep2021_advisory.asc