IBM Security Bulletin: Vulnerabilities in IBM SDK for Node.js affect IBM Business Process Manager Configuration Editor

Security vulnerabilities have been reported for IBM SDK for Node.js. IBM Business Process Manager includes a stand-alone tool for editing configuration properties files that is based IBM SDK for Node.js (CVE-2016-2086, CVE-2016-2216, CVE-2015-3197, CVE-2016-0705, CVE-2016-0797, CVE-2016-0702).

CVE(s): CVE-2016-2086, CVE-2016-2216, CVE-2015-3197, CVE-2016-0705, CVE-2016-0797, CVE-2016-0702

Affected product(s) and affected version(s):

  • IBM Business Process Manager all editions V8.5.5
  • IBM Business Process Manager all editions V8.5.6 including cumulative fix 2
  • IBM Business Process Manager all editions V8.5.7 before cumulative fix 1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/28SnRvh
X-Force Database: http://ift.tt/28RLis6
X-Force Database: http://ift.tt/28SnNM5
X-Force Database: http://ift.tt/1rd26hw
X-Force Database: http://ift.tt/1Tg5wqO
X-Force Database: http://ift.tt/1Tg5wqQ
X-Force Database: http://ift.tt/1Tg5v6h



from IBM Product Security Incident Response Team http://ift.tt/28RLeIU