IBM Security Bulletin: A security vulnerability has been identified in IBM Tivoli / Security Directory Server

Web Administration tool is shipped with IBM Tivoli / Security Directory Server. It is susceptible to a path traversal issue.

CVE(s): CVE-2015-1977

Affected product(s) and affected version(s):

IBM Tivoli Directory Server Version 6.1.0.73 and earlier
IBM Tivoli Directory Server Version 6.2.0.49 and earlier
IBM Tivoli Directory Server Version 6.3.0.42 and earlier
IBM Security Directory Server Version 6.3.1.17 and earlier
IBM Security Directory Server Version 6.4.0.8 and earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2a2hLcR
X-Force Database: http://ift.tt/29yRFzb



from IBM Product Security Incident Response Team http://ift.tt/2a2hIgO