QID 330129

Date Published: 2023-03-08

QID 330129: IBM AIX Java Multiple Vulnerabilities (java_dec2022_advisory)

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Versions 7, 7.1, 8 used by AIX.

Affected Versions:
AIX 7.1, 7.2, 7.3

QID Detection Logic (Authenticated):
The detection posts vulnerable if the installed package version is less than the patched version and interim fixes are also not installed.

Successful attacks of this vulnerability to cause low confidentiality impact and low integrity impact

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX advisory
    Software Advisories
    Advisory ID Software Component Link
    java_dec2022_advisory URL Logo aix.software.ibm.com/aix/efixes/security/java_dec2022_advisory.asc