IBM Watson Discovery for IBM Cloud Pak for Data is shipped with versions of FasterXML jackson-databind vulnerable to serialization gadgets.
Affected product(s) and affected version(s):
Affected Product(s) | Version(s) |
ICP – Discovery | 1.0.0-2.0.1 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/pages/node/1126401
The post Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in FasterXML jackson-databind appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/33SpeoY
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.