Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Tivoli Composite Application Manager for Transactions affected by multiple vulnerabilities in IBM JRE (Multiple CVEs)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM Tivoli Composite Application Manager for Transactions is shipped with two IBM JREs that are based on Oracle Java. It is also dependent on ITM 6.2.1 Framework, which also has it own JRE. Oracle has released a October 2013 Critical Patch Update (CPU) that contains security vulnerability fixes and IBM Java is affected. CVE(s): CVE-2013-5456, CVE-2013-5457, CVE-2013-5458, CVE-2013-4041, CVE-2013-5375, CVE-2013-5372, CVE-2013-5843, CVE-2013-5789, CVE-2013-5830, CVE-2013-5829, CVE-2013-5787,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_composite_application_manager_for_transactions_affected_by_multiple_vulnerabilities_in_ibm_jre_multiple_cves?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2013-5802 ,CVE-2013-4002 ,CVE-2013-5825 ,CVE-2013-5372 ,CVE-2013-0599 ,CVE-2013-0464 ,CVE-2013-0467 ,CVE-2013-2962 ,CVE-2013-2415 ,CVE-2013-4353 ,CVE-2013-6449 ,CVE-2013-4310 ,CVE-2013-4316 ,CVE-2013-2251 ,CVE-2013-2248 ,CVE-2013-2135 ,CVE-2013-2134 ,CVE-2013-2115 ,CVE-2013-5456 ,CVE-2013-5457 ,CVE-2013-5458 ,CVE-2013-4041 ,CVE-2013-5375 ,CVE-2013-5843 ,CVE-2013-5789 ,CVE-2013-5830 ,CVE-2013-5829 ,CVE-2013-5787 ,CVE-2013-5788 ,CVE-2013-5824 ,CVE-2013-5842 ,CVE-2013-5782 ,CVE-2013-5817 ,CVE-2013-5809 ,CVE-2013-5814 ,CVE-2013-5832 ,CVE-2013-5850 ,CVE-2013-5838 ,CVE-2013-5812 ,CVE-2013-5804 ,CVE-2013-5783 ,CVE-2013-3829 ,CVE-2013-5823 ,CVE-2013-5831 ,CVE-2013-5820 ,CVE-2013-5819 ,CVE-2013-5818 ,CVE-2013-5848 ,CVE-2013-5776 ,CVE-2013-5774 ,CVE-2013-5840 ,CVE-2013-5801 ,CVE-2013-5778 ,CVE-2013-5851 ,CVE-2013-5800 ,CVE-2013-5784 ,CVE-2013-5849 ,CVE-2013-5790 ,CVE-2013-5780 ,CVE-2013-5797 ,CVE-2013-5803 and CVE-2013-5772.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT