IBM Security Bulletin:Multiple vulnerabilities in IBM Java SDK 7 affect IBM Systems Director (CVE-2016-0264, CVE-2016-3426)

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 7 that is used by IBM Systems Director . These issues were disclosed as part of the IBM Java SDK updates in April 2016.

CVE(s): CVE-2016-3426, CVE-2016-0264

Affected product(s) and affected version(s):

From the IBM System Director command line enter smcli lsver to determine the level of IBM System Director installed.

IBM Systems Director:

  • 5.2.x.x
  • 6.1.x.x
  • 6.2.0.x
  • 6.2.1.x
  • 6.3.0.0
  • 6.3.1.x
  • 6.3.2.x
  • 6.3.3.x
  • 6.3.5.0
  • 6.3.6.0
  • 6.3.7.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eeGhZN
X-Force Database: http://ift.tt/1N2N2xe
X-Force Database: http://ift.tt/1Tg5wqG



from IBM Product Security Incident Response Team http://ift.tt/2e1hihh