Thursday, March 30, 2017

IBM Security Bulletin: IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management vulnerable to cross-site request forgery (CSRF)

The “notice confirmation” functionality in IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite, is impacted by a vulnerability that allows cross-site request forgery. Both products have addressed this vulnerability.

CVE(s): CVE-2016-6100

Affected product(s) and affected version(s):

IBM Disposal and Governance Management for IT v6.0 – 6.0.2
IBM Global Retention Policy and Schedule Management v6.0 – 6.0.2
IBM Disposal and Governance Management for IT v6.0.3 – 6.0.3.4
IBM Global Retention Policy and Schedule Management v6.0.3 – 6.0.3.4

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2nzipFk
X-Force Database: http://ift.tt/2ocmy4M

The post IBM Security Bulletin: IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management vulnerable to cross-site request forgery (CSRF) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2nzmKZ7

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.