IBM Security Bulletin: Vulnerability in Apache Commons FileUpload affects IBM InfoSphere Information Server (CVE-2016-3092)
An Apache Commons FileUpload vulnerability while processing file upload requests was addressed by IBM InfoSphere Information Server.
CVE(s): CVE-2016-3092
Affected product(s) and affected version(s):
The following product, running on all supported platforms, is affected:
IBM InfoSphere Information Server: versions 8.5, 8.7, 9.1, 11.3, and 11.5
IBM InfoSphere Metadata Asset Manager: versions 8.7, 9.1, 11.3, and 11.5
IBM InfoSphere QualityStage: versions 9.1, 11.3, and 11.5
IBM InfoSphere Metadata Workbench: versions 8.7, and 9.1
IBM InfoSphere Information Governance Catalog: versions 11.3, and 11.5
IBM InfoSphere Business Glossary: version 9.1
IBM InfoSphere Information Server Business Glossary Client for Eclipse: versions 9.1, 11.3, and 11.5
IBM InfoSphere Information Server Blueprint Director: versions 9.1, and 11.3
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2gYq0tQ
X-Force Database: http://ift.tt/2bozrA8
from IBM Product Security Incident Response Team http://ift.tt/2gYq24W