The “notice confirmation” functionality in IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite, is impacted by a vulnerability that allows cross-site request forgery. Both products have addressed this vulnerability.
CVE(s): CVE-2016-6100
Affected product(s) and affected version(s):
IBM Disposal and Governance Management for IT v6.0 – 6.0.2
IBM Global Retention Policy and Schedule Management v6.0 – 6.0.2
IBM Disposal and Governance Management for IT v6.0.3 – 6.0.3.4
IBM Global Retention Policy and Schedule Management v6.0.3 – 6.0.3.4
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2nzipFk
X-Force Database: http://ift.tt/2ocmy4M
The post IBM Security Bulletin: IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management vulnerable to cross-site request forgery (CSRF) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2nzmKZ7
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.