Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in IBM Java SDK affects IBM® DB2® LUW (CVE-2015-7575)

   
Affected software IBM
 
There is a vulnerability in IBM® SDK Java™ Technology Edition, Version 6.0 and 7.0 that is used by DB2 LUW. This vulnerability, commonly referred to as “SLOTH”, was disclosed as part of the IBM Java SDK updates in January 2016. CVE(s): CVE-2015-7575 Affected product(s) and affected version(s): Customers who have Java stored procedures using Secure Sockets Layer (SSL) API from IBM JDK are affected. All fix pack levels of IBM DB2 V9.7, V10.1 and V10.5 editions listed

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ibm_java_sdk_affects_ibm_db2_luw_cve_2015_7575?lang=en_us