Tuesday, September 27, 2016

Automation, AI among key takeaways for security execs, ecosystem

ISC Releases Security Updates for BIND

IBM Security Bulletin: A security vulnerability has been identified in WebSphere Liberty Profile shipped with IBM License Metric Tool v9 and IBM BigFix Inventory v9 (CVE-2016-3485)

WebSphere Liberty Profile is shipped as a component of IBM License Metric Tool v9 and IBM BigFix Inventory v9. Information about a security vulnerability affecting WebSphere Liberty Profile has been published in a security bulletin.

CVE(s): CVE-2016-3485

Affected product(s) and affected version(s):

Principal Product and Version(s) Affected Supporting Product and Version
IBM License Metric Tool 9
IBM BigFix Inventory 9
WebSphere Liberty Profile 8.5.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dpvTOq
X-Force Database: http://ift.tt/2b7G65u



from IBM Product Security Incident Response Team http://ift.tt/2dpwoIo

IBM Security Bulletin: Multiple Vulnerabilities in Oracle Outside In Technology affect IBM Rational DOORS Next Generation (CVE-2016-3574, CVE-2016-3575, etc)

IBM Rational DOORS Next Generation® is affected by multiple vulnerabilities in the Oracle Outside In Technology® that is used as a component.

CVE(s): CVE-2016-3574, CVE-2016-3575, CVE-2016-3576, CVE-2016-3577, CVE-2016-3578, CVE-2016-3579, CVE-2016-3580, CVE-2016-3581, CVE-2016-3582, CVE-2016-3583, CVE-2016-3590, CVE-2016-3591, CVE-2016-3592, CVE-2016-3593, CVE-2016-3594, CVE-2016-3595, CVE-2016-3596

Affected product(s) and affected version(s):

Rational DOORS Next Generation 6.0.2
Rational DOORS Next Generation 6.0.1
Rational DOORS Next Generation 6.0
Rational DOORS Next Generation 5.0.2
Releases prior to 5.0.2 are not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dpx1Sk
X-Force Database: http://ift.tt/2bylWyg
X-Force Database: http://ift.tt/2bH5oaQ
X-Force Database: http://ift.tt/2bylccF
X-Force Database: http://ift.tt/2bH5csb
X-Force Database: http://ift.tt/2byleBc
X-Force Database: http://ift.tt/2bH57EM
X-Force Database: http://ift.tt/2byl2Sz
X-Force Database: http://ift.tt/2bH5YFE
X-Force Database: http://ift.tt/2bylccG
X-Force Database: http://ift.tt/2bH6aoe
X-Force Database: http://ift.tt/2bylmR8
X-Force Database: http://ift.tt/2bH5cZl
X-Force Database: http://ift.tt/2bykTOU
X-Force Database: http://ift.tt/2bH6js1
X-Force Database: http://ift.tt/2byknk7
X-Force Database: http://ift.tt/2bH5P52
X-Force Database: http://ift.tt/2byl1xY



from IBM Product Security Incident Response Team http://ift.tt/2dpx0gZ

IBM Security Bulletin: Security Vulnerability in Apache Commons FileUpload affects IBM WebSphere Dashboard Framework (CVE-2016-3092 )

Apache Commons FileUpload, which is bundled with IBM WebSphere Dashboard Framework, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVE(s): CVE-2016-3092

Affected product(s) and affected version(s):

WebSphere Dashboard Framework 7.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2d4gFDh
X-Force Database: http://ift.tt/2bozrA8



from IBM Product Security Incident Response Team http://ift.tt/2dpyXKe

IBM Security Bulletin: Security Vulnerability in Apache Commons FileUpload affects IBM Web Experience Factory (CVE-2016-3092 )

Apache Commons FileUpload, which is bundled with IBM Web Experience Factory, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVE(s): CVE-2016-3092

Affected product(s) and affected version(s):

Web Experience Factory 8.0.0.0 – 8.0.0.3

Web Experience Factory 8.5.0.0 – 8.5.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2d4gszJ
X-Force Database: http://ift.tt/2bozrA8



from IBM Product Security Incident Response Team http://ift.tt/2dpwWxH

IBM Security Bulletin: Vulnerability in Apache Tomcat affects IBM Algo Credit Limits (CVE-2016-3092)

Apache Tomcat is vulnerable to a denial of service, caused by an error in the Apache Commons FileUpload component, and is supplied with IBM Algo Credit Limits. By sending file upload requests, an attacker could exploit this vulnerability to cause the server to become unresponsive.

CVE(s): CVE-2016-3092

Affected product(s) and affected version(s):

IBM Algo Credit Limits 4.7 and earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dpx1BO
X-Force Database: http://ift.tt/2bozrA8



from IBM Product Security Incident Response Team http://ift.tt/2dpwsrm