IBM Security Bulletin: Vulnerabilities in IBM FileNet Content Manager and IBM Content Foundation Installers (CVE-2016-4560)

InstallAnywhere generate installation executables which are vulnerable to an DLL-planting vulnerability.

CVE(s): CVE-2016-4560

Affected product(s) and affected version(s):

FileNet Content Manager 5.1.0, 5.2.0, 5.2.1
IBM Content Foundation 5.2.0, 5.2.1
FileNet Business Process Manager 4.5.1, 5.0.0
FileNet eProcess 5.2.0

All the below Windows releases and prior are affected:
4.5.1.4-P8PE-FP004
5.0.0.9-P8PE-FP009
4.5.1.8-P8CE-FP008
5.0.0.4-P8CE-FP004
5.1.0.6-P8CE-FP006
5.2.0.4-P8CPE-FP004
5.2.0.4-P8CaseFoundation-FP004
5.2.0.4-P8CSS-FP004
5.2.1.4-P8CPE-FP004
5.2.1.4-P8CaseFoundation-FP004
5.2.1.4-P8CSS-FP004
5.0.0.0-P8LCSE
5.1.0.2-CFS-FP002
5.2.0.2-CFS-FP002
5.2.1.3-CFS-FP003
5.2.0.2-P8RE-FP002
5.0.0.5-P8CA-FP005
eProcess-5.2.0-002

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1OlfjzK
X-Force Database: http://ift.tt/1Vw3dW4



from IBM Product Security Incident Response Team http://ift.tt/1OleMhg