<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2024-27267 java vulnerability of IBM in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231791#M38733</link>
    <description>&lt;P&gt;This one is for IBM:&lt;/P&gt;
&lt;DIV class="clearfix text-formatted field field--name-field-vulnerability-details field--type-text-long field--label-above"&gt;
&lt;P class="ibm-northstart-documentation-information-data"&gt;&lt;STRONG&gt;CVEID: &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284573" rel="nofollow" target="_blank"&gt;CVE-2024-27267&lt;/A&gt;&lt;BR /&gt;&lt;STRONG&gt;DESCRIPTION: &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;The Object Request Broker (ORB) in IBM SDK, Java Technology Edition is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.&lt;BR /&gt;CVSS Base score: 5.9&lt;BR /&gt;CVSS Temporal Score: See:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284573" rel="nofollow" target="_blank"&gt;https://exchange.xforce.ibmcloud.com/vulnerabilities/284573&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for the current score.&lt;BR /&gt;CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="clearfix text-formatted field field--name-field-affected-products field--type-text-long field--label-above"&gt;
&lt;H2 class="ibm-h4 ibm-bold ibm-northstart-documentation-information-label"&gt;Affected Products and Versions&lt;/H2&gt;
&lt;DIV&gt;
&lt;TABLE border="1"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Affected Product(s)&lt;/TD&gt;
&lt;TD&gt;Version(s)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;IBM SDK, Java Technology Edition&lt;/TD&gt;
&lt;TD&gt;7.1.0.0 - 7.1.5.18 (restricted access)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;IBM SDK, Java Technology Edition&lt;/TD&gt;
&lt;TD&gt;8.0.0.0 - 8.0.8.26&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;For detailed information on which CVEs affect which releases, please refer to the&amp;nbsp;&lt;A href="https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities" rel="nofollow" target="_blank"&gt;IBM SDK, Java Technology Edition Security Vulnerabilities page&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 05 Nov 2024 21:45:22 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-11-05T21:45:22Z</dc:date>
    <item>
      <title>CVE-2024-27267 java vulnerability of IBM</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231602#M38692</link>
      <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;Please let me know if Check Point is affected by this vulnerability, if not kindly leave a link to the article that discusses about this CVE.&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;FirewallHead&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 05:34:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231602#M38692</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2024-11-04T05:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2024-27267 java vulnerability of IBM</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231663#M38715</link>
      <description>&lt;P&gt;I would engage with the TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 18:14:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231663#M38715</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-04T18:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2024-27267 java vulnerability of IBM</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231791#M38733</link>
      <description>&lt;P&gt;This one is for IBM:&lt;/P&gt;
&lt;DIV class="clearfix text-formatted field field--name-field-vulnerability-details field--type-text-long field--label-above"&gt;
&lt;P class="ibm-northstart-documentation-information-data"&gt;&lt;STRONG&gt;CVEID: &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284573" rel="nofollow" target="_blank"&gt;CVE-2024-27267&lt;/A&gt;&lt;BR /&gt;&lt;STRONG&gt;DESCRIPTION: &amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;The Object Request Broker (ORB) in IBM SDK, Java Technology Edition is vulnerable to remote denial of service, caused by a race condition in the management of ORB listener threads.&lt;BR /&gt;CVSS Base score: 5.9&lt;BR /&gt;CVSS Temporal Score: See:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284573" rel="nofollow" target="_blank"&gt;https://exchange.xforce.ibmcloud.com/vulnerabilities/284573&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for the current score.&lt;BR /&gt;CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="clearfix text-formatted field field--name-field-affected-products field--type-text-long field--label-above"&gt;
&lt;H2 class="ibm-h4 ibm-bold ibm-northstart-documentation-information-label"&gt;Affected Products and Versions&lt;/H2&gt;
&lt;DIV&gt;
&lt;TABLE border="1"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Affected Product(s)&lt;/TD&gt;
&lt;TD&gt;Version(s)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;IBM SDK, Java Technology Edition&lt;/TD&gt;
&lt;TD&gt;7.1.0.0 - 7.1.5.18 (restricted access)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;IBM SDK, Java Technology Edition&lt;/TD&gt;
&lt;TD&gt;8.0.0.0 - 8.0.8.26&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;For detailed information on which CVEs affect which releases, please refer to the&amp;nbsp;&lt;A href="https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities" rel="nofollow" target="_blank"&gt;IBM SDK, Java Technology Edition Security Vulnerabilities page&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Nov 2024 21:45:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231791#M38733</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-05T21:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2024-27267 java vulnerability of IBM</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231832#M38738</link>
      <description>&lt;P&gt;# java -version&lt;BR /&gt;java version "1.8.0_401"&lt;BR /&gt;Java(TM) SE Runtime Environment (build 8.0.8.21 - pxi3280sr8fp21-20240221_01(SR8 FP21))&lt;BR /&gt;IBM J9 VM (build 2.9, JRE 1.8.0 Linux x86-32-Bit 20240216_65882 (JIT enabled, AO T enabled)&lt;BR /&gt;OpenJ9 - 6a2a245&lt;BR /&gt;OMR - 9440e34&lt;BR /&gt;IBM - 7394519)&lt;BR /&gt;JCL - 20231221_01 based on Oracle jdk8u401-b10&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 09:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231832#M38738</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-11-06T09:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2024-27267 java vulnerability of IBM</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231872#M38747</link>
      <description>&lt;P&gt;In general, the ability to exploit the vulnerabilities here are low since:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Gateways don't actually use java (though the binaries are there)&lt;/LI&gt;
&lt;LI&gt;On Management, the relevant Java processes are reversed proxied through Apache, which limits the external&amp;nbsp;&lt;SPAN&gt;traffic that can reach the inner processes and thus exploit the relevant CVE.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It appears that we are planning to release fixes in upcoming JHFs, in any case.&lt;BR /&gt;TAC should be consulted for further details: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 15:14:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CVE-2024-27267-java-vulnerability-of-IBM/m-p/231872#M38747</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-06T15:14:47Z</dc:date>
    </item>
  </channel>
</rss>

