IBM Security Bulletin: Weakness in generated service credentials affects multiple Watson Developer Cloud services (CVE-2016-0931)

A weakness in generated service credentials that affects multiple Watson Developer Cloud offered through IBM Bluemix has been identified and fixed. Replacement of previously generated credentials is recommended.

CVE(s): CVE-2016-0391

Affected product(s) and affected version(s):

The following Watson Developer Cloud Services on Bluemix are affected:

– Concept Expansion

– Concept Insights

– Dialog

– Document Conversion

– Language Translation

– Natural Language Classifier

– Personality Insights

– Relationship Extraction

– Retrieve and Rank

– Speech to Text

– Text to Speech

– Tone Analyzer

– Tradeoff Analytics

– Visual Insights

– Visual Recognition

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/28KXc4N
X-Force Database: http://ift.tt/28Lw1ua



from IBM Product Security Incident Response Team http://ift.tt/28KXaKe