• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Patches Multiple Java Security Vulnerabilities in IBM i

    September 17, 2013 Alex Woodie

    IBM last week acknowledged that it quietly patched a number of potentially critical security vulnerabilities in IBM i that could enable hackers to compromise, spoof, and gain privileged access to an affected system. The problems stem mostly from flaws in Java that Oracle disclosed in June, and which impact the Java Runtime and Java Software Development Kit (JRE/JDK) for all supported releases of the OS, from i5/OS V5R4 through IBM i 7.1.

    On Friday, Secunia issued an advisory that disclosed the existence of multiple security vulnerabilities in IBM i, as recorded by official CVE reference numbers. The security organization stated:

    “IBM has acknowledged multiple vulnerabilities in IBM i, which can be exploited by malicious, local users to disclose certain sensitive information, manipulate certain data, and gain escalated privileges and by malicious people to conduct spoofing attacks, disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.”

    IBM issued a security bulletin that affirmed that 45 separate flaws, as depicted through individual CVE listings, that can impact IBM i. Most of those stem from the June disclosure of security flaws from Oracle, but there were eight additional flaws patched that weren’t from that Oracle batch.

    IBM says there were several vulnerabilities that affected multiple components, including CVE-2013-3006 through CVE-2013-3012. “These vulnerabilities allow code running under a security manager to escalate its privileges by modifying or removing the security manager,” IBM says in its security advisory. “Some of the issues need to be combined in sequence to achieve an exploit. The vulnerabilities could occur when untrusted code is executed under a security manager, or when the IBM Java SDK has been associated with a Web browser for running applets and Web Start applications.”

    IBM patched the flaws with updates to three group PTFs, including:

    SF99562 level 25, which addresses the 32-bit JDK for IBM i 6.1 and 7.1 and was last updated August 29;

    SF99572 level 14, which addresses the 64-bit JDK for IBM i 6.1 and 7.1 and was last updated August 29;

    and SF99291 level 34, which addresses the 32-bit JDK for i5/OS V5R4 and was last updated August 29.

    RELATED STORIES

    IBM Highlights Critical Security Vulnerabilities with New Tool

    The 10-Year Security Itch Needs Scratching

    New Java Vulnerabilities No Threat To IBM i



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Raz-Lee Security

    Start your Road to Zero Trust!

    Firewall Network security, controlling Exit Points, Open DB’s and SSH. Rule Wizards and graphical BI.

    Request Demo

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Abacus Solutions:  Save Time & Money with Cloud Storage for Your IBM i Environment
    Cybernetics:  Ditch the tape backup? Up to 4.3 TB/hr! Start saving now!
    System i Developer:  Upgrade your skills at the RPG & DB2 Summit in Minneapolis, Oct 15-17.

    More IT Jungle Resources:

    System i PTF Guide: Weekly PTF Updates
    IBM i Events Calendar: National Conferences, Local Events, and Webinars
    Breaking News: News Hot Off The Press
    TPM @ The Reg: More News From ITJ EIC Timothy Prickett Morgan

    IBM Sells Off BPO Services Biz To Synnex For $505 Million Kwik Trip Stops at RJS for Doc Management

    Leave a Reply Cancel reply

Volume 13, Number 25 -- September 17, 2013
THIS ISSUE SPONSORED BY:

PowerTech
Maxava
Abacus Solutions
HiT Software
Profound Logic Software

Table of Contents

  • Kwik Trip Stops at RJS for Doc Management
  • PSGi Offers Help for Neglected IBM i Servers
  • IBM Patches Multiple Java Security Vulnerabilities in IBM i
  • LANSA Adds Goodies to LongRange Mobile App
  • Halcyon Goes GUI with Job Scheduler
  • Interest in Simulated Role Swaps the Real Deal, Maxava Says
  • Spinnaker Solves Payroll Issue for Big JDE World Customer
  • EVault Scales Its Backup Appliances Up and Down
  • Vegas Casino Expands IBM i Footprint
  • ASNA Helps Steel Company Off Big Iron

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Liam Allan Shares What’s Coming Next With Code For IBM i
  • From Stable To Scalable: Visual LANSA 16 Powers IBM i Growth – Launching July 8
  • VS Code Will Be The Heart Of The Modern IBM i Platform
  • The AS/400: A 37-Year-Old Dog That Loves To Learn New Tricks
  • IBM i PTF Guide, Volume 27, Number 25
  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle