IBM Security Bulletin: Vulnerabilities in XML processing affect IBM DataPower Gateways
IBM DataPower Gateways has addressed vulnerabilities in processing certain XML files that could cause a denial of service or obtain sensitive information.
CVE(s): CVE-2016-4448, CVE-2016-4449, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447
Affected product(s) and affected version(s):
IBM DataPower Gateways versions 7.2.0.0 to 7.2.0.8, 7.5.0.0 to 7.5.0.2, and 7.5.1.0 to 7.5.1.1.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2djlEyr
X-Force Database: http://ift.tt/29hoGgb
X-Force Database: http://ift.tt/29qou1O
X-Force Database: http://ift.tt/2b1F6Qx
X-Force Database: http://ift.tt/1syye00
X-Force Database: http://ift.tt/29qofDU
from IBM Product Security Incident Response Team http://ift.tt/2djmz1L