IBM Security Bulletin: Multiple security vulnerabilities in IBM Business Process Manager affect IBM Cloud Orchestrator (CVE-2015-7407, CVE-2015-7400, CVE-2015-7454)

IBM Business Process Manager that is bundled with IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition, has identified multiple vulnerabilites. IBM Cloud Orchestrator V2.4, has addressed these vulnerabilites . It includes IBM Business Process Manager V8.5.6 CF2.

CVE(s): CVE-2015-7407, CVE-2015-7400, CVE-2015-7454

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2g3Sv8W
X-Force Database: http://ift.tt/2gqu75n
X-Force Database: http://ift.tt/2g3R1eY
X-Force Database: http://ift.tt/2gqtsR5

Affected Principal Product and VersionAffected Supporting Product and Version
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.4, V2.4.0.1, V2.4.0.2, V2.4.0.3IBM Business Process Manager V8.5.5 through V8.5.6
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.3, V2.3.0.1IBM Business Process Manager V8.5.0.1


from IBM Product Security Incident Response Team http://ift.tt/2g3QOIs