Vulnerability Bulletins

IBM Security Bulletin: InfoSphere Streams is possibly affected by vulnerabilities in the IBM® SDK, Java™ Technology Edition (CVE-2014-0453 and CVE-2014-0460)


System information

   
Affected software IBM

Description

The IBM® Developers Kit, Java™ Technology Edition that is shipped with InfoSphere Streams has security vulnerabilities two of which could potentially affect InfoSphere Streams. Other vulnerabilities could be exposed by the use of custom Java code in InfoSphere Streams applications. Customers are advised to evaluate the identified vulnerabilities along with their Java code and take appropriate action if these security exposures affect their systems. CVE(s): CVE-2014-0453,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_infosphere_streams_is_possibly_affected_by_vulnerabilities_in_the_ibm_sdk_java_technology_edition_cve_2014_0453_and_cve_2014_0460?lang=en_us

Standar resources

Property Value
CVE CVE-2014-0453 ,CVE-2014-0460 ,CVE-2014-0114 ,CVE-2014-0411 ,CVE-2011-4858 ,CVE-2014-0878 ,CVE-2014-0457 ,CVE-2014-2421 ,CVE-2014-0429 ,CVE-2014-0461 ,CVE-2014-0455 ,CVE-2014-2428 ,CVE-2014-0448 ,CVE-2014-0454 ,CVE-2014-0446 ,CVE-2014-0452 ,CVE-2014-0451 ,CVE-2014-2402 ,CVE-2014-2423 ,CVE-2014-2427 ,CVE-2014-0458 ,CVE-2014-2414 ,CVE-2014-2412 ,CVE-2014-2409 ,CVE-2013-6954 ,CVE-2013-6629 ,CVE-2014-2401 ,CVE-2014-0449 ,CVE-2014-0459 ,CVE-2014-2398 ,CVE-2014-1876 and CVE-2014-2420.

Version history

Version Comments Date
1.0 Advisory issued 2014-06-06
Ministerio de Defensa
CNI
CCN
CCN-CERT