Monday, January 9, 2017

IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor

Security vulnerabilities have been reported for IBM SDK for Node.js. IBM Business Process Manager includes a stand-alone tool for editing configuration properties files that is based IBM SDK for Node.js.

CVE(s): CVE-2016-6304, CVE-2016-6303, CVE-2016-2178, CVE-2016-6306, CVE-2016-2183, CVE-2016-7099, CVE-2016-5325,

Affected product(s) and affected version(s):

  • IBM Business Process Manager Advanced V8.5.5.0 – V8.5.7.0 prior to cumulative fix 2016.12

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2hP0EBR
X-Force Database: http://ift.tt/2dmY7tO
X-Force Database: http://ift.tt/2dmXjFz
X-Force Database: http://ift.tt/2asKHex
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2dckDn3
X-Force Database: http://ift.tt/2e5C4fq
X-Force Database: http://ift.tt/2gwBF0V



from IBM Product Security Incident Response Team http://ift.tt/2iVJ3I0

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.