• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • IBM Patches Multiple Java Security Vulnerabilities in IBM i

    September 17, 2013 Alex Woodie

    IBM last week acknowledged that it quietly patched a number of potentially critical security vulnerabilities in IBM i that could enable hackers to compromise, spoof, and gain privileged access to an affected system. The problems stem mostly from flaws in Java that Oracle disclosed in June, and which impact the Java Runtime and Java Software Development Kit (JRE/JDK) for all supported releases of the OS, from i5/OS V5R4 through IBM i 7.1.

    On Friday, Secunia issued an advisory that disclosed the existence of multiple security vulnerabilities in IBM i, as recorded by official CVE reference numbers. The security organization stated:

    “IBM has acknowledged multiple vulnerabilities in IBM i, which can be exploited by malicious, local users to disclose certain sensitive information, manipulate certain data, and gain escalated privileges and by malicious people to conduct spoofing attacks, disclose certain sensitive information, manipulate certain data, cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.”

    IBM issued a security bulletin that affirmed that 45 separate flaws, as depicted through individual CVE listings, that can impact IBM i. Most of those stem from the June disclosure of security flaws from Oracle, but there were eight additional flaws patched that weren’t from that Oracle batch.

    IBM says there were several vulnerabilities that affected multiple components, including CVE-2013-3006 through CVE-2013-3012. “These vulnerabilities allow code running under a security manager to escalate its privileges by modifying or removing the security manager,” IBM says in its security advisory. “Some of the issues need to be combined in sequence to achieve an exploit. The vulnerabilities could occur when untrusted code is executed under a security manager, or when the IBM Java SDK has been associated with a Web browser for running applets and Web Start applications.”

    IBM patched the flaws with updates to three group PTFs, including:

    SF99562 level 25, which addresses the 32-bit JDK for IBM i 6.1 and 7.1 and was last updated August 29;

    SF99572 level 14, which addresses the 64-bit JDK for IBM i 6.1 and 7.1 and was last updated August 29;

    and SF99291 level 34, which addresses the 32-bit JDK for i5/OS V5R4 and was last updated August 29.

    RELATED STORIES

    IBM Highlights Critical Security Vulnerabilities with New Tool

    The 10-Year Security Itch Needs Scratching

    New Java Vulnerabilities No Threat To IBM i



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Midrange Dynamics North America

    Git up to speed with MDChange!

    Git can be lightning-fast when dealing with just a few hundred items in a repository. But when dealing with tens of thousands of items, transaction wait times can take minutes.

    MDChange offers an elegant solution that enables you to work efficiently any size Git repository while making your Git experience seamless and highly responsive.

    Learn more.

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Abacus Solutions:  Save Time & Money with Cloud Storage for Your IBM i Environment
    Cybernetics:  Ditch the tape backup? Up to 4.3 TB/hr! Start saving now!
    System i Developer:  Upgrade your skills at the RPG & DB2 Summit in Minneapolis, Oct 15-17.

    More IT Jungle Resources:

    System i PTF Guide: Weekly PTF Updates
    IBM i Events Calendar: National Conferences, Local Events, and Webinars
    Breaking News: News Hot Off The Press
    TPM @ The Reg: More News From ITJ EIC Timothy Prickett Morgan

    IBM Sells Off BPO Services Biz To Synnex For $505 Million Kwik Trip Stops at RJS for Doc Management

    Leave a Reply Cancel reply

Volume 13, Number 25 -- September 17, 2013
THIS ISSUE SPONSORED BY:

PowerTech
Maxava
Abacus Solutions
HiT Software
Profound Logic Software

Table of Contents

  • Kwik Trip Stops at RJS for Doc Management
  • PSGi Offers Help for Neglected IBM i Servers
  • IBM Patches Multiple Java Security Vulnerabilities in IBM i
  • LANSA Adds Goodies to LongRange Mobile App
  • Halcyon Goes GUI with Job Scheduler
  • Interest in Simulated Role Swaps the Real Deal, Maxava Says
  • Spinnaker Solves Payroll Issue for Big JDE World Customer
  • EVault Scales Its Backup Appliances Up and Down
  • Vegas Casino Expands IBM i Footprint
  • ASNA Helps Steel Company Off Big Iron

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle