<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp;amp; FW) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109111#M14790</link>
    <description>&lt;P&gt;Just because a vulnerability scanner finds a “vulnerable version” doesn’t mean a vulnerability exists or that it’s exploitable.&lt;/P&gt;
&lt;P&gt;One of the CVEs is actually in Eclipse, which we don’t even use.&lt;BR /&gt;The other CVE is in a function we don’t use.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 02:59:38 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-01-28T02:59:38Z</dc:date>
    <item>
      <title>Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp; FW)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/108945#M14773</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;Customer has Internal Nexpose Scan machine and they gave VA Report on CheckPoint IP address for below CVE's:&lt;/P&gt;&lt;P&gt;IBM Java: IBM Security Update July 2019 (&lt;STRONG&gt;CVE-2019-11775&lt;/STRONG&gt;)&lt;BR /&gt;IBM Java: Oracle July 14 2020 CPU (&lt;STRONG&gt;CVE-2020-14621&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;Information:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;Vulnerable software installed: IBM JRE 7.0.10.45 (/opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties)&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Solution:&amp;nbsp;&lt;/SPAN&gt;Upgrade IBM Java to version &lt;STRONG&gt;7.0.10.50&lt;/STRONG&gt; or &lt;STRONG&gt;7.1.4.50&lt;/STRONG&gt; or &lt;STRONG&gt;8.0.5.40&lt;/STRONG&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;On CheckPoint command output:&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@FWSTDR8040:0]# more /opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties&lt;BR /&gt;#Created by Ant MergeProperties&lt;BR /&gt;#Wed Apr 10 06:42:31 BST 2019&lt;BR /&gt;sdk.version=pxi3270sr10fp45-20190410_01(SR10 FP45)&lt;BR /&gt;&lt;STRONG&gt;sdk.vrmf.version=7.0.10.45&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What steps is needed to be actioned on CheckPoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 08:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/108945#M14773</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-01-27T08:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp; FW)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109052#M14780</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Are you in contact with TAC regarding this issue?&lt;/P&gt;
&lt;P&gt;They will engage the relevant area to advise further on this and provide a response.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 14:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109052#M14780</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-01-27T14:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp; FW)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109065#M14783</link>
      <description>&lt;P&gt;Hi Chris - Not yet as I'm still implementing solution for customer.&lt;/P&gt;&lt;P&gt;So wanna check if anyone has idea on this.&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109065#M14783</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-01-27T15:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp; FW)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109111#M14790</link>
      <description>&lt;P&gt;Just because a vulnerability scanner finds a “vulnerable version” doesn’t mean a vulnerability exists or that it’s exploitable.&lt;/P&gt;
&lt;P&gt;One of the CVEs is actually in Eclipse, which we don’t even use.&lt;BR /&gt;The other CVE is in a function we don’t use.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 02:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109111#M14790</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-28T02:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server &amp; FW)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109134#M14792</link>
      <description>&lt;P&gt;Thanks much PhoneBoy..&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 06:05:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vulnerable-software-installed-IBM-JRE-7-0-10-45-in-CheckPoint/m-p/109134#M14792</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-01-28T06:05:36Z</dc:date>
    </item>
  </channel>
</rss>

