There are vulnerabilities in deserialization of openid connect cookie used by IBM Streams. IBM Streams has addressed the applicable CVEs.
CVE(s): CVE-2018-1851
Affected product(s) and affected version(s):
| Affected InfoSphere Streams | Affected Versions |
|---|---|
| InfoSphere Streams | 4.0.1.6 and earlier |
| InfoSphere Streams | 3.2.1.6 and earlier |
| IBM Streams | 4.1.1.7 and earlier |
| IBM Streams | 4.2.1.5 and earlier |
| IBM Streams | 4.3.0.0 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10872056
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/150999
The post IBM Security Bulletin: Vulnerabilities in deserialization of openid connect cookie appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2Oi8pNT
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.