IBM Security Bulletin: The Elastic Storage Server and the GPFS Storage Server are affected by a vulnerability in IBM Spectrum Scale (CVE-2016-2985 and CVE-2016-2984)

There are vulnerabilities in IBM Spectrum Scale packaged with IBM Spectrum Scale RAID for the Elastic Storage Server and the GPFS Storage Server.

CVE(s): CVE-2016-2985, CVE-2016-2984

Affected product(s) and affected version(s):

The Elastic Storage Server versions 4.0, 3.5, 3.0 and 2.5

The GPFS Storage Server version 2.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dfrRrG
X-Force Database: http://ift.tt/2arxFw4
X-Force Database: http://ift.tt/2aDMcrO



from IBM Product Security Incident Response Team http://ift.tt/2cRVCnb