Rational Performance Tester and Rational Service Tester vulnerabilities due to security vulnerabilities in IBM JRE 1.5, 1.6 & 1.7 (CVE-2014-0411, CVE-2014-4263, CVE-2014-4244) Summary A potential security vulnerability exists in the IBM Java Runtime Environment component of IBM Rational Performance Tester and Rational Service Tester related to the use of SSL/TLS and RSA. Patches for these vulnerabilities are available in IBM JRE 7 (SR7 FP1). Vulnerability Details CVE ID: CVE-2014-0411 CVSS Base Score: 4 CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/90357 for the current score CVSS Environmental Score*: Undefined CVSS Vector: (AV/N:AC/H:Au/N:C/P:I/P:A/N) CVEID: CVE-2014-4263 DESCRIPTION: An unspecified vulnerability related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact. CVSS Base Score: 4 CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/94606 for the current score CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N) CVEID: CVE-2014-4244 DESCRIPTION: An unspecified vulnerability related to the Security component has partial confidentiality impact, partial integrity impact, and no availability impact. CVSS Base Score: 4 CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/94605 for the current score CVSS Environmental Score*: Undefined CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N) Java 1.7 SR7 FP1 downloads are available from Fix Central. Download the SDK appropriate for your platform in order to manually replace the JDK or JRE.