IBM Security Bulletin: A JMX component vulnerability in IBM Java SDK and IBM WebSphere Application Server affects IBM Emptoris Strategic Supply Management Suite and IBM Emptoris Services Procurement (CVE-2016-3427)

The IBM Emptoris Strategic Supply Management Suite and IBM Emptoris Services Procurement products are affected by a JMX component security vulnerability that exists in IBM SDK Java Technology Edition and IBM WebSphere Application Server. This issue was disclosed as part of the IBM Java SDK updates in April 2016.

CVE(s): CVE-2016-3427

Affected product(s) and affected version(s):

IBM Emptoris Contract Management 9.5 through 10.1
IBM Emptoris Program Management 10.0.0 through 10.1
IBM Emptoris Sourcing 10.0.0 through 10.1
IBM Emptoris Spend Analysis 10.0.0 through 10.1
IBM Emptoris Supplier Lifecycle Management 9.5 through 10.1
IBM Emptoris Strategic Supply Management 10.0.0 through 10.1
IBM Emptoris Services Procurement 10.0.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/29G9ADg
X-Force Database: http://ift.tt/1N2N48r



from IBM Product Security Incident Response Team http://ift.tt/29G9U4B