IBM Security Bulletin: Spice-server vulnerabilities affect IBM SmartCloud Entry (CVE-2016-0749 CVE-2016-2150 )

SmartCloud Entry is vulerable to Spice-server vulnerabilities. Attackers could exploit them to cause improper bounds checking by smartcard interaction or bypass security restrictions

CVE(s): CVE-2016-0749, CVE-2016-2150

Affected product(s) and affected version(s):

IBM SmartCloud Entry 3.2 through Appliance fix pack 21

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cYvciV
X-Force Database: http://ift.tt/2cKMi0d
X-Force Database: http://ift.tt/2cYujH9



from IBM Product Security Incident Response Team http://ift.tt/2cKLc4O