-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.3232
         Security Bulletin: CVE-2021-2341 may affect IBM SDK, Java
                            Technology Edition
                             28 September 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM Java
Publisher:         IBM
Operating System:  UNIX variants (UNIX, Linux, OSX)
                   Windows
Impact/Access:     Access Confidential Data -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-2341  

Reference:         ASB-2021.0144
                   ESB-2021.3058
                   ESB-2021.3040
                   ESB-2021.2943.2

Original Bulletin: 
   https://www.ibm.com/support/pages/node/6488425

- --------------------------BEGIN INCLUDED TEXT--------------------

CVE-2021-2341 may affect IBM SDK, Java Technology Edition

Document Information

Document number    : 6488425
Modified date      : 24 September 2021
Product            : IBM Java
Software version   : All versions
Operating system(s): Platform Independent

Summary

CVE-2021-2341 was disclosed as part of the Oracle July 2021 Critical Patch
Update.

Vulnerability Details

CVEID: CVE-2021-2341
DESCRIPTION: An unspecified vulnerability in Java SE related to the Networking
component could allow an unauthenticated attacker to obtain sensitive
information resulting in a low confidentiality impact using unknown attack
vectors.
CVSS Base score: 3.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/
205768 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

7.0.0.0 - 7.0.10.90
7.1.0.0 - 7.1.4.90
8.0.0.0 - 8.0.6.30
11.0.9.0 - 11.0.11.0

Remediation/Fixes

8.0.6.35
IBM Semeru 11.0.12.0

Note: IBM SDK, Java Technology Edition version 11 is now IBM Semeru 11
Certified Edition. Future vulnerability fixes for IBM Semeru Certified Edition
will be described in security bulletins for IBM Semeru.

IBM SDK, Java Technology Edition releases can be downloaded, subject to the
terms of the developerWorks license, from the Java Developer Center .

IBM Semeru releases can be downloaded from the IBM Semeru Developer Center .

IBM customers requiring an update for an SDK shipped with an IBM product should
contact IBM support , and/or refer to the appropriate product security
bulletin.

Workarounds and Mitigations

None

Oracle July 2021 Java SE Critical Patch Update Advisory
 IBM SDK, Java Technology Edition Security Vulnerabilities

Acknowledgement

Change History

13 Sep 2021: Initial Publication
24 Sep 2021: Corrected fixed release information for Java 8

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYVJ2X+NLKJtyKPYoAQh/Lg/+MsQXQwNoB9srK/29OwueUWcUnW5NEhfH
4gyr/pfh4aK2TNHtVsJ3NH3BO9bj6i5XD/2UYq9aekOGFWpJQL5xvmdAF8tHVvkw
i/asG8wS1uLLS++cI63p6Q0RrYmmzG5coJv0cvnuiiFvQN1MSq5aq/IbU+oVpcpw
AukMUJK0zvRTeXEMZYwBQx4kTW4nvrReBqjjlCzUrLcpOfad7gNGWhdBZ1duCEbE
pVVIxyap8+90F0soKV8e8qQ1+KisWKVX082XJ+MwkLOkU1BsyY8dUCZSa3knWrGp
mMdKzlkIlpH9XgOaV5YdIsSoXVL2HkiGV1K8AGIlSEgQ+6cZQn+ZvZGTWSJSt8YT
sEZQeycyCnJkjNVS9I7r1+Rwe0/igJdadXpa9n0KumCqZO8ZoAkhwh/iV/uKvTNQ
LqnyCNRQLv71YoO8m00dQU3puCe0ZzNVn5kMLDb8Zocgwvt1P4uX+DR24ER55JWR
09L9Ra7OGWVpey/Lq5KLkIovyUFs5VA7rrOioxNZ+HSYScXb7XhAU1LVA4R8XxC8
CBfJ3GknbF8weD+jWalRl6Fz6gx0fcZ93ELmDnqBCiAKghABEcx3tQ1VOI1Py2Y1
41OtY6BDkeZwPVzb458tRHQH8m6ZmQjt6ydtK2QErS3EYvb9+JdIIqv9vtdbHI+y
Z/4SVRyPce0=
=VcGG
-----END PGP SIGNATURE-----