IBM Security Bulletin: Multiple Security Vulnerabilities exist in IBM Cognos TM1

Several vulnerabilities have been addressed for: IBM SDK, Java Technology Edition Quarterly CPU – Jul 2016; Recover Password with Valid Session Key; System Name Stored Cross-site Scripting; TM1 Server Stack Exhaustion Denial of Service; OpenSource OpenSSL; Sweet32: Birthday attacks on 64-bit block ciphers in TLS (openssl) and Opensource Apache Tomcat, Commons FileUpload Vulnerabilities

CVE(s): CVE-2000-1254, CVE-2016-2177, CVE-2016-2180, CVE-2016-2183, CVE-2016-3036, CVE-2016-3037, CVE-2016-3038, CVE-2016-3092, CVE-2016-3485, CVE-2016-6304

Affected product(s) and affected version(s):

  • IBM Cognos TM1 10.1
  • IBM Cognos TM1 10.2
  • IBM Cognos TM1 10.2.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2phwasP
X-Force Database: http://ift.tt/2gJ8WYq
X-Force Database: http://ift.tt/2aPXjQq
X-Force Database: http://ift.tt/2dmWOvf
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2phBdJC
X-Force Database: http://ift.tt/2nMHD6x
X-Force Database: http://ift.tt/2phw6Jp
X-Force Database: http://ift.tt/2bozrA8
X-Force Database: http://ift.tt/2b7G65u
X-Force Database: http://ift.tt/2dmY7tO

The post IBM Security Bulletin: Multiple Security Vulnerabilities exist in IBM Cognos TM1 appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2phxgo7