IBM Security Bulletin: Httpd vulnerability affects IBM SmartCloud Entry (CVE-2016-5387)

IBM SmartCloud Entry is vulnerable to httpd vulnerabilities. An attacker could exploit this vulnerability to redirect outbound HTTP traffic to arbitrary proxy server.

CVE(s): CVE-2016-5387

Affected product(s) and affected version(s):

IBM SmartCloud Entry 2.2.0 through 2.2.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.3.0 through 2.3.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.4.0 through 2.4.0.4 Appliance fix pack 6
IBM SmartCloud Entry 3.1.0 through 3.1.0.4 Appliance fix pack 21
IBM SmartCloud Entry 3.2.0 through 3.2.0.4 Appliance fix pack 21

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cEDkDY
X-Force Database: http://ift.tt/2aO8XMj



from IBM Product Security Incident Response Team http://ift.tt/2cNmxMg