IBM Security Bulletin: Multiple vulnerabilities affect IBM Tivoli Monitoring embedded WebSphere Application Server

The following security issues have been identified in WebSphere Application Server included as part of IBM Tivoli Monitoring (ITM) portal server.

CVE(s): CVE-2016-0359, CVE-2016-0377, CVE-2016-1181, CVE-2016-1182, CVE-2016-3598, CVE-2016-3511, CVE-2016-3485, CVE-2016-3092

Affected product(s) and affected version(s):

IBM Tivoli Monitoring versions 6.3.0 through 6.3.0 FP7 – Tivoli Enterprise Portal Server (TEPS) all CVEs above.

IBM Tivoli Monitoring versions 6.2.3 through 6.2.3 FP5 – Tivoli Enterprise Portal Server (TEPS) all CVE’s above.

IBM Tivoli Monitoring versions 6.2.2 through 6.2.2 FP9 – Tivoli Enterprise Portal Server (TEPS) CVE-2016-3092 only.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2dR4okn
X-Force Database: http://ift.tt/28YBUiZ
X-Force Database: http://ift.tt/2bH6inX
X-Force Database: http://ift.tt/2974C3a
X-Force Database: http://ift.tt/29tkNpV
X-Force Database: http://ift.tt/2aGcUP3
X-Force Database: http://ift.tt/2b7Gtgl
X-Force Database: http://ift.tt/2b7G65u
X-Force Database: http://ift.tt/2bozrA8



from IBM Product Security Incident Response Team http://ift.tt/2dmY1m1