Hello CheckMates,
Customer has Internal Nexpose Scan machine and they gave VA Report on CheckPoint IP address for below CVE's:
IBM Java: IBM Security Update July 2019 (CVE-2019-11775)
IBM Java: Oracle July 14 2020 CPU (CVE-2020-14621)
Information:
"Vulnerable software installed: IBM JRE 7.0.10.45 (/opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties)"
Solution: Upgrade IBM Java to version 7.0.10.50 or 7.1.4.50 or 8.0.5.40"
On CheckPoint command output:
[Expert@FWSTDR8040:0]# more /opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties
#Created by Ant MergeProperties
#Wed Apr 10 06:42:31 BST 2019
sdk.version=pxi3270sr10fp45-20190410_01(SR10 FP45)
sdk.vrmf.version=7.0.10.45
What steps is needed to be actioned on CheckPoint.
Regards, Prabu