-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2014.0128
          Security Bulletin: Multiple vulnerabilities in current
               releases of IBM SDK, Java Technology Edition
                              31 January 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Java
Publisher:         IBM
Operating System:  AIX
                   HP-UX
                   Linux variants
                   Solaris
                   Windows
                   z/OS
Impact/Access:     Execute Arbitrary Code/Commands -- Remote/Unauthenticated
                   Modify Arbitrary Files          -- Remote/Unauthenticated
                   Denial of Service               -- Remote/Unauthenticated
                   Access Confidential Data        -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2014-0428 CVE-2014-0424 CVE-2014-0423
                   CVE-2014-0422 CVE-2014-0417 CVE-2014-0416
                   CVE-2014-0415 CVE-2014-0411 CVE-2014-0410
                   CVE-2014-0403 CVE-2014-0387 CVE-2014-0376
                   CVE-2014-0375 CVE-2014-0373 CVE-2014-0368
                   CVE-2013-5910 CVE-2013-5907 CVE-2013-5899
                   CVE-2013-5898 CVE-2013-5896 CVE-2013-5889
                   CVE-2013-5888 CVE-2013-5887 CVE-2013-5884
                   CVE-2013-5878  

Reference:         ASB-2014.0005
                   ESB-2014.0114
                   ESB-2014.0102
                   ESB-2014.0065
                   ESB-2014.0058

Original Bulletin: 
   http://www-01.ibm.com/support/docview.wss?uid=swg21662968

- --------------------------BEGIN INCLUDED TEXT--------------------

Security Bulletin: Multiple vulnerabilities in current releases of IBM
SDK, Java Technology Edition

Document information
More support for:

Runtimes for Java Technology
Java Class Libraries

Software version:
5.0, 6.0, 6.1, 7.0, 7.1

Operating system(s):
AIX, HP-UX, Linux, Linux zSeries, Solaris, Windows, z/OS

Software edition:
J2SE, Java SE

Reference #:
1662968

Modified date:
2014-01-30

Summary

Java SE issues disclosed in the Oracle January 2014 Critical Patch Update
Vulnerability Details

CVE IDs: CVE-2014-0428 CVE-2014-0422 CVE-2013-5907 CVE-2014-0415
CVE-2014-0410 CVE-2013-5889 CVE-2014-0417 CVE-2014-0387 CVE-2014-0424
CVE-2013-5878 CVE-2014-0373 CVE-2014-0375 CVE-2014-0403 CVE-2014-0423
CVE-2014-0376 CVE-2013-5910 CVE-2013-5884 CVE-2013-5896 CVE-2013-5899
CVE-2014-0416 CVE-2013-5887 CVE-2014-0368 CVE-2013-5888 CVE-2013-5898
CVE-2014-0411

DESCRIPTION: This bulletin covers all applicable Java SE CVEs published
by Oracle as part of their January 2014 Critical Patch Update. For more
information please refer to Oracle's January 2014 CPU Advisory and the
X-Force database entries referenced below.

CVEID: CVE-2014-0428
CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90325 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0422
CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90326 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)

CVEID: CVE-2013-5907
CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90324 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0415
CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90323 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0410
CVSS Base Score: 10
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90322 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/C:I/C:A/C)

CVEID: CVE-2013-5889
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90328 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/M:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0417
CVSS Base Score: 9.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90331 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/M:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0387
CVSS Base Score: 7.6
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90332 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/H:Au/N:C/C:I/C:A/C)

CVEID: CVE-2014-0424
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90333 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/P:A/P)

CVEID: CVE-2013-5878
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90335 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/P:A/P)

CVEID: CVE-2014-0373
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90334 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/P:A/P)

CVEID: CVE-2014-0375
CVSS Base Score: 5.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90339 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/M:Au/N:C/P:I/P:A/N)

CVEID: CVE-2014-0403
CVSS Base Score: 5.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90338 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/M:Au/N:C/P:I/P:A/N)

CVEID: CVE-2014-0423
CVSS Base Score: 5.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90340 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/S:C/P:I/N:A/P)

CVEID: CVE-2014-0376
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90350 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/N:I/P:A/N)

CVEID: CVE-2013-5910
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90352 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/N:I/P:A/N)

CVEID: CVE-2013-5884
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90348 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/N:A/N)

CVEID: CVE-2013-5896
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90347 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/N:I/N:A/P)

CVEID: CVE-2013-5899
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90346 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/N:A/N)

CVEID: CVE-2014-0416
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90349 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/N:I/P:A/N)

CVEID: CVE-2013-5887
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90345 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/N:I/N:A/P)

CVEID: CVE-2014-0368
CVSS Base Score: 5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90351 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/L:Au/N:C/P:I/N:A/N)

CVEID: CVE-2013-5888
CVSS Base Score: 4.6
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90354 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/L:AC/L:Au/N:C/P:I/P:A/P)

CVEID: CVE-2013-5898
CVSS Base Score: 4
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90356 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/H:Au/N:C/P:I/P:A/N)

CVEID: CVE-2014-0411
CVSS Base Score: 4
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90357 for the
current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV/N:AC/H:Au/N:C/P:I/P:A/N)
Affected Products

IBM SDK, Java 2 Technology Edition, Version 5.0 Service Refresh 16 Fix
Pack 4 and earlier
IBM SDK, Java Technology Edition, Version 6 Service Refresh 15 and earlier
IBM SDK, Java Technology Edition, Version 6.0.1 Service Refresh 7 and earlier
IBM SDK, Java Technology Edition, Version 7 Service Refresh 6 and earlier
IBM SDK, Java Technology Edition, Version 7 Release 1 GA
Remediation/Fixes

IBM SDK, Java 2 Technology Edition, Version 5.0 Service Refresh 16 Fix
Pack 5 and later
IBM SDK, Java Technology Edition, Version 6 Service Refresh 15 Fix Pack
1 and later
IBM SDK, Java Technology Edition, Version 6.0.1 Service Refresh 7 Fix Pack
1 and later
IBM SDK, Java Technology Edition, Version 7 Service Refresh 6 Fix Pack 1
and later
IBM SDK, Java Technology Edition, Version 7 Release 1 Service Refresh 1
and later

For detailed information on which CVEs affect which releases, please refer
to the IBM SDK, Java Technology Edition Security Alerts page.

IBM SDK, Java Technology Edition releases can be downloaded, subject to
the terms of the developerWorks license, from here

IBM customers requiring an update for an SDK shipped with an IBM product
should contact IBM support, and/or refer to the appropriate product
security bulletin.

APAR numbers are as follows:

IX90133 (CVE-2014-0428)
IV54081 (CVE-2014-0422)
IV54086 (CVE-2013-5907)
IV54088 (CVE-2014-0415)
IV54089 (CVE-2014-0410)
IV54090 (CVE-2013-5889)
IV54091 (CVE-2014-0417)
IV54094 (CVE-2014-0387)
IV54095 (CVE-2014-0424)
IV54096 (CVE-2013-5878)
IV54097 (CVE-2014-0373)
IV54099 (CVE-2014-0375)
IV54100 (CVE-2014-0403)
IV54101 (CVE-2014-0423)
IV54103 (CVE-2014-0376)
IV54105 (CVE-2013-5910)
IV54143 (CVE-2013-5884)
IV54106 (CVE-2013-5896)
IV54107 (CVE-2013-5899)
IV54108 (CVE-2014-0416)
IV54110 (CVE-2013-5887)
IV54111 (CVE-2014-0368)
IV54113 (CVE-2013-5888)
IV54114 (CVE-2013-5898)
IV54115 (CVE-2014-0411)
Important note:

IBM strongly suggests that all System z customers be subscribed to the
System z Security Portal to receive the latest critical System z security
and integrity service. If you are not subscribed, see the instructions
on the System z Security web site. Security and integrity APARs and
associated fixes will be posted to this portal. IBM suggests reviewing
the CVSS scores and applying all security or integrity fixes as soon as
possible to minimize any potential risk.
References:
Complete CVSS Guide
On-line Calculator V2
Oracle January 2014 Java SE Critical Patch Update Advisory
IBM SDK, Java Technology Edition Security Alerts

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the impact
of this vulnerability in their environments by accessing the links in the
Reference section of this Security Bulletin.

Note: According to the Forum of Incident Response and Security Teams (FIRST),
the Common Vulnerability Scoring System (CVSS) is an "industry open standard
designed to convey vulnerability severity and help to determine urgency
and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT
WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND
FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING
THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBUu7hoxLndAQH1ShLAQJLAA/+JsLb2OOpTRWGMjFPLnsWHFjAOJ8a6Y58
Gly2byddSPRDKu95nbXGriNgN4q2Jn85uRfH3UgO7AQ4A8vZN5cxM/rS4j+M97I3
ZGjG1LK1ShG/voONhrOMYsFAqgG+MMVJmFQfyg3TcZZMbmkmL9EgjTyOW985T3ZM
eicJIW8X0HRsMKEgXKFlIBUabzNCV9gD7ItbpePnv/GK/s6eWAomnZxlnBlt780r
8auOYYcKn3LKC9YcolT9LH5WopZE1DMjdMNGqwqQhPKSX6rhNrO9tSkUJ0+nH7BQ
QDFp9nixtJl7nHvrfpDIjsuRE3eqehcwIOQNRdBjjAHZ3J21YqeFG9raFthRonEA
0xWS0CE/X9GieeRhfYuCIGjyEAXCMiJ7lFflw7EKCjDyjOEkucfQIamVixJDW75o
1LeEujH7o74RCTeWkLNzSEyFtp1udqlrFEMGc1KOLOwunSaENWcClAOBTXedFhO6
/lGaz6aVFvf2xEunUNh0NKQvJ4JYRCCUyeTTe583drnlg51mXRS0NAaFzOnOL+hs
NXWXumYfHO19TRiiXFpbe9wycftcDKpuQJwN77l8Z3qVvGGigncNGK6135HnS5au
Diw/1kmWQjerLsmC+cHMuEmgfk7VuW0whSwxzvswWnyU/D+El35br6oLDH16LgqG
YdeLfTSTcjc=
=xddL
-----END PGP SIGNATURE-----