IBM Security Bulletin: IBM Streams may be impacted by a vulnerability in WebSphere Liberty (CVE-2016-2923)

There is an information disclosure vulnerability in IBM WebSphere Application Server Liberty for any users of the JAX-RS API which may impact IBM Streams. The IBM Streams team has addressed this vulnerability.

CVE(s): CVE-2016-2923

Affected product(s) and affected version(s):

  • IBM Streams Version 4.1.1.1 and earlier
  • IBM InfoSphere Streams Version 4.0.1.2 and earlier
  • IBM InfoSphere Streams Version 3.2.1.5 and earlier
  • IBM InfoSphere Streams Version 3.1.0.7 and earlier
  • IBM InfoSphere Streams Version 3.0.0.5 and earlier
  • IBM InfoSphere Streams Version 2.0.0.4 and earlier
  • IBM InfoSphere Streams Version 1.2.1.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cZwpkN
X-Force Database: http://ift.tt/28XWbJc



from IBM Product Security Incident Response Team http://ift.tt/2cZwXHz