IBM Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server Liberty which may impact IBM Streams (CVE-2016-0378)
IBM WebSphere Application Server (WAS) Liberty profile is shipped as a component of IBM Streams. Information about a security vulnerabilities affecting WAS Liberty profile has been published in a security bulletin.
CVE(s): CVE-2016-0378
Affected product(s) and affected version(s):
- IBM Streams Version 4.2.0.0
- IBM InfoSphere Streams Version 4.1.1.1 and earlier
- IBM InfoSphere Streams Version 4.0.1.2 and earlier
- IBM InfoSphere Streams Version 3.2.1.5 and earlier
- IBM InfoSphere Streams Version 3.1.0.7 and earlier
- IBM InfoSphere Streams Version 3.0.0.5 and earlier
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21993571
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/112240
from IBM Product Security Incident Response Team https://www.ibm.com/blogs/psirt/ibm-security-bulletin-a-security-vulnerability-has-been-identified-in-ibm-websphere-application-server-liberty-which-may-impact-ibm-streams-cve-2016-0378/