IBM Security Bulletin: IBM TRIRIGA Application Unintended Proxy or Intermediary (CVE-2016-0362)

IBM TRIRIGA platform allows remote attackers to use one of its web services as a proxy to forward HTTP requests to other internal/external Web resources.

CVE(s): CVE-2016-0362

Affected product(s) and affected version(s):

The following IBM TRIRIGA Application Platform versions are affected.
· IBM TRIRIGA Application Platform 3.5.
· IBM TRIRIGA Application Platform 3.4.
· IBM TRIRIGA Application Platform 3.3.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1TPYRK1
X-Force Database: http://ift.tt/1TJLTID



from IBM Product Security Incident Response Team http://ift.tt/1TPYWxw