Vulnerability Bulletins

IBM Security Bulletin: InfoSphere Streams Applications Using Custom Java Operators May Be Affected by Vulnerabilities in the IBM SDK Java Technology Edition


System information

   
Affected software IBM

Description

The IBM® Developers Kit, Java™ Technology Edition that is shipped with InfoSphere Streams has security vulnerabilities which can potentially impact InfoSphere Streams applications. None of these vulnerabilities exist in InfoSphere Streams code but might impact customers who implement custom Java operators. Customers are advised to evaluate their custom operators and take appropriate action if security exposures are found. CVE(s): CVE-2013-5456, CVE-2013-5457, CVE-2013-5458,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_infosphere_streams_applications_using_custom_java_operators_may_be_affected_by_vulnerabilities_in_the_ibm_sdk_java_technology_edition?lang=en_us

Standar resources

Property Value
CVE CVE-2014-0160 ,CVE-2014-0076 ,CVE-2013-4353 ,CVE-2013-6449 ,CVE-2014-0827 ,CVE-2013-5456 ,CVE-2013-5457 ,CVE-2013-5458 ,CVE-2013-4041 ,CVE-2013-5375 ,CVE-2013-5372 ,CVE-2013-5843 ,CVE-2013-5789 ,CVE-2013-5830 ,CVE-2013-5829 ,CVE-2013-5787 ,CVE-2013-5788 ,CVE-2013-5824 ,CVE-2013-5842 ,CVE-2013-5782 ,CVE-2013-5817 ,CVE-2013-5809 ,CVE-2013-5814 ,CVE-2013-5832 ,CVE-2013-5850 ,CVE-2013-5838 ,CVE-2013-5802 ,CVE-2013-5812 ,CVE-2013-5804 ,CVE-2013-5783 ,CVE-2013-3829 ,CVE-2013-5823 ,CVE-2013-5831 ,CVE-2013-5820 ,CVE-2013-5819 ,CVE-2013-5818 ,CVE-2013-5848 ,CVE-2013-5776 ,CVE-2013-5774 ,CVE-2013-5825 ,CVE-2013-5840 ,CVE-2013-5801 ,CVE-2013-5778 ,CVE-2013-5851 ,CVE-2013-5800 ,CVE-2013-5784 ,CVE-2013-5849 ,CVE-2013-5790 ,CVE-2013-5780 ,CVE-2013-5797 ,CVE-2013-5803 and CVE-2013-5772.

Version history

Version Comments Date
1.0 Advisory issued 2014-04-23
Ministerio de Defensa
CNI
CCN
CCN-CERT