IBM Security Bulletin: Potential Denial of Service and Information Disclosure that affect IBM WebSphere Application Server for Bluemix (CVE-2016-8919, CVE-2016-9736)

There is a potential denial of service with WebSphere Application Server with SOAP connectors. There is a potential information disclosure in WebSphere Application Server using malformed SOAP requests on WebSphere Application Server.

CVE(s): CVE-2016-8919, CVE-2016-9736

Affected product(s) and affected version(s):

This vulnerability affects the following versions and releases of IBM WebSphere Application Server:

  • Version 9.0
  • Version 8.5.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2k9I3jH
X-Force Database: http://ift.tt/2iIIHRy
X-Force Database: http://ift.tt/2iIJjGM



from IBM Product Security Incident Response Team http://ift.tt/2k3D9m9