IBM Security Bulletin: IBM Expeditor HarfBuzz is vulnerable to a denial of service information disclosure (CVE-2015-8947)
IBM Expeditor is consuming XULRunner 1.0.6 version. A fix was provided to avoid denial of service or an unspecified impact.
CVE(s): CVE-2015-8947
Affected product(s) and affected version(s):
IBM Expeditor 6.2.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dFDBDe
X-Force Database: http://ift.tt/2cOHWDv
from IBM Product Security Incident Response Team http://ift.tt/2d0fDFs