Vulnerability Bulletins

IBM Security Bulletin: IBM Tivoli NetView for z/OS (distributed components) affected by multiple vulnerabilities in IBM JRE and in eWAS v7.0 (Multiple CVEs)

   
Affected software IBM
 
Vulnerabilities have been identified in the IBM JRE and eWAS v7.0 components utilized by IBM Tivoli NetView for z/OS distributed components. The IBM JRE vulnerabilities originate from two unspecified vulnerabilities fixed in the January 2014 and April 2014 Oracle Java CPUs. In addition, an eWAS v7.0 optional install script may allow elevation of privileges. CVE(s): CVE-2014-0411, CVE-2014-0453 and CVE-2014-3020 Affected product(s) and affected version(s): · This vulnerability is

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_netview_for_z_os_distributed_components_affected_by_multiple_vulnerabilities_in_ibm_jre_and_in_ewas_v7_0_multiple_cves?lang=en_us