Monday, November 6, 2017

IBM Security Bulletin: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise (CVE-2017-1137)

There is a security vulnerability in WebSphere Application Server, IBM Business Process Manager, and IBM Tivoli System Automation Application Manager that is shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise. Additionally, the vulnerability affects Jazz™ for Service Management that is shipped with Cloud Orchestrator Enterprise.

CVE(s): CVE-2017-1137

Affected product(s) and affected version(s):

Principal Product and Version(s)
Affected Supporting Product and Version

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2AfB8e9
X-Force Database: http://ift.tt/2szfCxV

The post IBM Security Bulletin: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise (CVE-2017-1137) appeared first on IBM PSIRT Blog.

IBM Cloud Orchestrator V2.5.0.3 and V2.5.0.4
  • WebSphere Application Server V8.5.5.11
  • Business Process Manager 8.5.5 through V8.5.7 CF201703
  • IBM Tivoli System Automation Application Manager V4.1
IBM Cloud Orchestrator V2.4.0.3 and V2.4.0.4
  • WebSphere Application Server V8.5.5.12
  • IBM Business Process Manager Standard V8.5.0.1 through 8.5.6 CF2
  • IBM Tivoli System Automation Application Manager V4.1
IBM Cloud Orchestrator Enterprise V2.5.0.3 and V2.5.0.4
  • WebSphere Application Server V8.5.5 through V8.5.5.11
  • IBM Tivoli System Automation Application Manager 4.1
  • Jazz™ for Service Management V1.1.0.1 through V1.1.2.1
IBM Cloud Orchestrator Enterprise V2.4.0.3 and V2.4.0.4
  • WebSphere Application Server V8.5.0.1 through V8.5.5.12
  • IBM Tivoli System Automation Application Manager 4.1
  • Jazz™ for Service Management V1.1.0.1 through V1.1.2.1


from IBM Product Security Incident Response Team http://ift.tt/2AdPJ9N

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.