IBM Security Bulletin: Httpd vulnerability affects IBM SmartCloud Entry (CVE-2016-5387)
IBM SmartCloud Entry is vulnerable to httpd vulnerabilities. An attacker could exploit this vulnerability to redirect outbound HTTP traffic to arbitrary proxy server.
CVE(s): CVE-2016-5387
Affected product(s) and affected version(s):
IBM SmartCloud Entry 2.2.0 through 2.2.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.3.0 through 2.3.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.4.0 through 2.4.0.4 Appliance fix pack 6
IBM SmartCloud Entry 3.1.0 through 3.1.0.4 Appliance fix pack 21
IBM SmartCloud Entry 3.2.0 through 3.2.0.4 Appliance fix pack 21
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cEDkDY
X-Force Database: http://ift.tt/2aO8XMj
from IBM Product Security Incident Response Team http://ift.tt/2cNmxMg