This bulletin addresses several security vulnerabilities. OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by IBM Cognos Controller. IBM Cognos Controller has addressed the applicable CVEs. There are multiple vulnerabilities in IBM® WebSphere Application Server Liberty. Liberty is used by IBM Cognos Controller version 10.2.1. These issues were disclosed as part of the IBM WebSphere Application Server Liberty updates. IBM Cognos Controller has addressed a vulnerability with Apache CommonsFileUpload affecting IBM Cognos Controller version 10.2.1 .
CVE(s): CVE-2016-0359, CVE-2016-6302, CVE-2016-6304, CVE-2016-6305, CVE-2016-6303, CVE-2016-2182, CVE-2016-2180, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-2181, CVE-2016-2183, CVE-2016-6309, CVE-2016-7052, CVE-2016-3092, CVE-2016-5983, CVE-2016-5986
Affected product(s) and affected version(s):
IBM Cognos Controller 10.1.0
IBM Cognos Controller 10.1.1
IBM Cognos Controller 10.2.0
IBM Cognos Controller 10.2.1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2mVySGJ
X-Force Database: http://ift.tt/28YBUiZ
X-Force Database: http://ift.tt/2dR4fNY
X-Force Database: http://ift.tt/2dmY7tO
X-Force Database: http://ift.tt/2dR3XX1
X-Force Database: http://ift.tt/2dmXjFz
X-Force Database: http://ift.tt/2dR45pA
X-Force Database: http://ift.tt/2dmWOvf
X-Force Database: http://ift.tt/2aPXjQq
X-Force Database: http://ift.tt/2asKHex
X-Force Database: http://ift.tt/2dR5fBu
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3Smm
X-Force Database: http://ift.tt/2dmYa8Y
X-Force Database: http://ift.tt/2dmXLUk
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2fn8D82
X-Force Database: http://ift.tt/2dTp6vD
X-Force Database: http://ift.tt/2bozrA8
X-Force Database: http://ift.tt/2cX6Wuu
X-Force Database: http://ift.tt/2ccJKps
The post IBM Security Bulletin: Multiple vulnerabilities have been identified in IBM Cognos Controller appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2nqMtlI
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.