QID 376149

Date Published: 2021-12-20

QID 376149: IBM Java Software Development Kit (SDK) Multiple Vulnerabilities (Oracle October 19 2021 CPU (1.7.0_321, 1.8.0_311))

IBM Java SDK are prone to multiple vulnerabilities that can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, bypass certain security restrictions, cause a denial of service and compromise a vulnerable system.

Affected Versions:
IBM Java SDK prior to 7.0.11.0
IBM Java SDK prior to 7.1.5.0
IBM Java SDK prior to 8.0.7.0

NOTE:
CVE-2021-35560 and CVE-2021-35578 are affected to IBM Java 8 only.

QID Detection Logic (Authenticated):
The QID runs "java -version" command to check if vulnerable IBM Java is installed on the system.

Successful exploitation of these vulnerabilities may affect the Confidentiality, Integrity and Availability.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Latest service refresh packs are available at IBM SDK, Java Technology Edition Download.
    Refer to Oracle October 19 2021 CPU to obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    IBM Java SDK(Oracle October 19 2021 CPU (1.7.0_321, 1.8.0_311)) URL Logo www.ibm.com/support/pages/java-sdk-security-vulnerabilities#Oracle_October_19_2021_CPU