IBM Security Bulletin: Vulnerabilities in OpenSource ICU4C may affect IBM Streams (CVE-2016-6293, CVE-2016-7415)

There are multiple vulnerabilities in OpenSource ICU4C used by IBM Streams. These issues may allow an attackers to perform a denial of service attack or potentially execute arbitrary code. IBM Streams has addressed these vulnerabilties.

CVE(s): CVE-2016-6293, CVE-2016-7415

Affected product(s) and affected version(s):

The following versions may be impacted:

  • IBM Streams Version 4.2.0.2 and earlier
  • IBM InfoSphere Streams Version 4.1.1.3 and earlier
  • IBM InfoSphere Streams Version 4.0.1.3 and earlier
  • IBM InfoSphere Streams Version 3.2.1.6 and earlier
  • IBM InfoSphere Streams Version 3.1.0.8 and earlier
  • IBM InfoSphere Streams Version 3.0.0.6 and earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2pcAKI8
X-Force Database: http://ift.tt/2gwvIRX
X-Force Database: http://ift.tt/2kw1oMC



from IBM Product Security Incident Response Team http://ift.tt/2pCqlIB