First published: Wed Jul 17 2013(Updated: )
The July 2013 updates for the IBM JDK (5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5) contain patches for unspecified security flaws. For the majority of the flaws, upstream has provided a CVSSv2 base score of 9.3, which suggests a CVSSv2 vector of AV:N/AC:M/Au:N/C:P/I:P/A:P. The exception is <a href="https://access.redhat.com/security/cve/CVE-2013-4002">CVE-2013-4002</a> with a CVSSv2 base score of 7.1. CVE CVSSv2 Score Fixed in <a href="https://access.redhat.com/security/cve/CVE-2013-3006">CVE-2013-3006</a> 9.3 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3007">CVE-2013-3007</a> 9.3 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3008">CVE-2013-3008</a> 9.3 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3009">CVE-2013-3009</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3010">CVE-2013-3010</a> 9.3 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3011">CVE-2013-3011</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3012">CVE-2013-3012</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-4002">CVE-2013-4002</a> 7.1 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 References: <a href="https://www.ibm.com/developerworks/java/jdk/alerts/">https://www.ibm.com/developerworks/java/jdk/alerts/</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j764/Java7_64.fixes.html#SR5">http://www.ibm.com/developerworks/java/jdk/aix/j764/Java7_64.fixes.html#SR5</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR14">http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR14</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j564/fixes.html#SR16FP3">http://www.ibm.com/developerworks/java/jdk/aix/j564/fixes.html#SR16FP3</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 | >=5.0 SR16-FP3<6.0.1 SR6>=6 SR14<7 SR5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-985501 is very high with a CVSSv2 base score of 9.3.
To fix REDHAT-BUG-985501, update to the latest version of IBM JDK as specified in the patch release.
Affected versions by REDHAT-BUG-985501 include IBM JDK 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, and 7 SR5.
REDHAT-BUG-985501 contains unspecified security flaws that could lead to potential information disclosure and unauthorized access.
As of now, no specific known exploits for REDHAT-BUG-985501 have been documented.