Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Prabulingam_N1
Advisor
Jump to solution

Vulnerable software installed: IBM JRE 7.0.10.45 in CheckPoint Products (Mgmt server & FW)

Hello CheckMates,

Customer has Internal Nexpose Scan machine and they gave VA Report on CheckPoint IP address for below CVE's:

IBM Java: IBM Security Update July 2019 (CVE-2019-11775)
IBM Java: Oracle July 14 2020 CPU (CVE-2020-14621)

Information:

"Vulnerable software installed: IBM JRE 7.0.10.45 (/opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties)"


Solution: 
Upgrade IBM Java to version 7.0.10.50 or 7.1.4.50 or 8.0.5.40"

On CheckPoint command output: 

[Expert@FWSTDR8040:0]# more /opt/CPsuite-R80.40/fw1/oracle_oi/cleancontent/jre/lib/version.properties
#Created by Ant MergeProperties
#Wed Apr 10 06:42:31 BST 2019
sdk.version=pxi3270sr10fp45-20190410_01(SR10 FP45)
sdk.vrmf.version=7.0.10.45

 

What steps is needed to be actioned on CheckPoint.

 

Regards, Prabu

 

0 Kudos
4 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events