QID 376150

QID 376150: IBM Java Software Development Kit (SDK) Multiple Vulnerabilities (CVE-2021-35550,CVE-2021-35561,CVE-2021-35603) (Oracle October 19 2021 CPU (1.7.0_321, 1.8.0_311))

IBM Java SDK are prone to multiple vulnerabilities that can be exploited by malicious people to disclose certain sensitive information, manipulate certain data, bypass certain security restrictions, cause a denial of service and compromise a vulnerable system.

Affected Versions:
IBM Java SDK prior to 7.0.11.5
IBM Java SDK prior to 7.1.5.5
IBM Java SDK prior to 8.0.7.5

QID Detection Logic (Authenticated):
The QID runs "java -version" command to check if vulnerable IBM Java is installed on the system.

Successful exploitation of these vulnerabilities may affect the Confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution
    Latest service refresh packs are available at IBM SDK, Java Technology Edition Download.
    Refer to Oracle October 19 2021 CPU to obtain more information.
    Vendor References

    CVEs related to QID 376150

    Software Advisories
    Advisory ID Software Component Link
    IBM Java SDK(Oracle October 19 2021 CPU (1.7.0_321, 1.8.0_311)) URL Logo www.ibm.com/support/pages/java-sdk-security-vulnerabilities#Oracle_October_19_2021_CPU