IBM Security Bulletin: Multiple vulnerabilities in Apache Tomcat affect IBM UrbanCode Deploy (CVE-2015-5345, CVE-2015-5346, CVE-2015-5351)

Multiple vulnerabilities in Apache Tomcat affect IBM UrbanCode Deploy.

CVE(s): CVE-2015-5345, CVE-2015-5346, CVE-2015-5351

Affected product(s) and affected version(s):

IBM UrbanCode Deploy 6.0, 6.0.1, 6.0.1.1, 6.0.1.2, 6.0.1.3, 6.0.1.4, 6.0.1.5, 6.0.1.6, 6.0.1.7, 6.0.1.8, 6.0.1.9, 6.0.1.10, 6.0.1.11, 6.0.1.12, 6.1, 6.1.0.1, 6.1.0.2, 6.1.0.3, 6.1.0.4, 6.1.1, 6.1.1.1, 6.1.1.2, 6.1.1.3, 6.1.1.4, 6.1.1.5, 6.1.1.6, 6.1.1.7, 6.1.1.8, 6.1.2, 6.1.3, 6.1.3.1, 6.1.3.2, 6.2, 6.2.0.1, 6.2.0.2, and 6.2.1 on all supported platforms.

IBM UrbanCode Deploy with Patterns 6.1.0 to 6.1.1.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/25RxeCP
X-Force Database: http://ift.tt/1rhWy5x
X-Force Database: http://ift.tt/1NSj9zW
X-Force Database: http://ift.tt/1rhWy5D



from IBM Product Security Incident Response Team http://ift.tt/25RxOQQ