IBM Security Bulletin:IBM WebSphere deserialization of untrusted data in IBM eDiscovery Manager
IBM WebSphere Application Server could allow remote attackers to execute arbitrary Java code with a serialized object from untrusted sources.
CVE(s): CVE-2016-5983
Affected product(s) and affected version(s):
IBM eDiscovery Manager Version 2.2.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2jXi6nC
X-Force Database: http://ift.tt/2cX6Wuu
from IBM Product Security Incident Response Team http://ift.tt/2jXkqLi