Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Tivoli NetView for z/OS (distributed components) affected by multiple vulnerabilities in IBM JRE and in eWAS v7.0 (Multiple CVEs)


Información sobre el sistema

   
Software afectado IBM

Descripción

Vulnerabilities have been identified in the IBM JRE and eWAS v7.0 components utilized by IBM Tivoli NetView for z/OS distributed components. The IBM JRE vulnerabilities originate from two unspecified vulnerabilities fixed in the January 2014 and April 2014 Oracle Java CPUs. In addition, an eWAS v7.0 optional install script may allow elevation of privileges. CVE(s): CVE-2014-0411, CVE-2014-0453 and CVE-2014-3020 Affected product(s) and affected version(s): · This vulnerability is

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_tivoli_netview_for_z_os_distributed_components_affected_by_multiple_vulnerabilities_in_ibm_jre_and_in_ewas_v7_0_multiple_cves?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0411 ,CVE-2014-0114 ,CVE-2014-0224 ,CVE-2014-0453 and CVE-2014-3020.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-02

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT