IBM Security Bulletin: Vulnerabilities in IBM Cloud Orchestrator (CVE-2016-0203, CVE-2015-7494)

IBM Cloud Orchestrator has identified Cross Domain Services Action and Virtual Machine Authentication vulnerabilities. IBM Cloud Orchestrator, formerly knonw as SmartCloud Orchestrator, has addressed these vulnerabilities.

CVE(s): CVE-2016-0203, CVE-2015-7494

Affected product(s) and affected version(s):

IBM Cloud Orchestrator V2.5, V2.5.01, V2.4. V2.4.0.1, V2.4.0.2, V2.4.0.3

IBM SmartCloud Orchestrator V2.3, V2.3.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2g3Qzxn
X-Force Database: http://ift.tt/2gqpt7a
X-Force Database: http://ift.tt/2g3OEZj



from IBM Product Security Incident Response Team http://ift.tt/2gqtt7B