Wednesday, March 27, 2019

IBM Security Bulletin: Content Collector for Email is affected by 3RD PARTY IBM WebSphere Application Server Deserialization

Content Collector for Email has addressed the following vulnerability. IBM WebSphere Application Server could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources.

CVE(s): CVE-2018-1904

Affected product(s) and affected version(s):

Content Collector for Email v4.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10791975
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152533

The post IBM Security Bulletin: Content Collector for Email is affected by 3RD PARTY IBM WebSphere Application Server Deserialization appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/2OtPmAD

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.