IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM Security Access Manager (CVE-2016-5597, CVE-2016-5554)

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 8 and IBM Runtime Environment Java Version 8 used by IBM Security Access Manager version 8 and 9 appliances. These issues were disclosed as part of the IBM Java SDK updates in October 2016.

CVE(s): CVE-2016-5597, CVE-2016-5554

Affected product(s) and affected version(s):

IBM Security Access Manager for Web version 8, all firmware versions

IBM Security Access Manager for Mobile version 8, all firmware versions

IBM Security Access Manager version 9, all firmware versions

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2qS08EQ
X-Force Database: http://ift.tt/2e5pD2s
X-Force Database: http://ift.tt/2eDqzaq

The post IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM Security Access Manager (CVE-2016-5597, CVE-2016-5554) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2q7lcde