IBM Security Bulletin: Vulnerabilities in Apache Tomcat affect the IBM FlashSystem models 840 and 900
Apr 24, 2017 10:00 am EDT
Categorized: High Severity
There are vulnerabilities in Apache Tomcat to which the IBM® FlashSystem™ 840 and FlashSystem™ 900 are susceptible. An exploit of these vulnerabilities (CVE-2016-6816, CVE-2016-6817, and CVE-2016-6796) could allow a remote attacker to obtain sensitive information, cause an application to enter an infinite loop, or bypass a configured SecurityManager,
CVE(s): CVE-2016-6816, CVE-2016-6817, CVE-2016-6796
Affected product(s) and affected version(s):
FlashSystem 840 machine type and models (MTMs) affected include 9840-AE1 and 9843-AE1.
FlashSystem 900 MTMs affected include 9840-AE2 and 9843-AE2.
Code versions affected include supported VRMFs:
· 1.4.0.0 – 1.4.5.0
· 1.3.0.0 – 1.3.0.6
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2oni8sz
X-Force Database: http://ift.tt/2iIaaqs
X-Force Database: http://ift.tt/2iIey8S
X-Force Database: http://ift.tt/2if6ZDc
from IBM Product Security Incident Response Team http://ift.tt/2pWfwz4