Friday, September 22, 2017

IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor

Security vulnerabilities have been reported for IBM SDK for Node.js. IBM Business Process Manager includes a stand-alone tool for editing configuration properties files that is based IBM SDK for Node.js.

CVE(s): CVE-2017-1000381, CVE-2017-11499

Affected product(s) and affected version(s):

  • IBM Business Process Manager V8.5.5.0 – V8.5.7.0 including cumulative fix 2017.06

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2xtkjxS
X-Force Database: http://ift.tt/2h8Xc5H
X-Force Database: http://ift.tt/2h8Xb1D

The post IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2wM3U3Y

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.