IBM JDK versions 6.0.16.45, 7.0.10.5, 7.1.4.5, and 8.0.4.5 correct a security issue described by upstream as:
CVEID: CVE-2017-1289 DESCRIPTION: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. CVSS Base Score: 8.2 CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125150 for the current score CVSS Environmental Score: Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)
References:
https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateMay2017 http://www-01.ibm.com/support/docview.wss?uid=swg22002169 https://exchange.xforce.ibmcloud.com/vulnerabilities/125150