IBM Security Bulletin: IBM Cognos Controller 2017Q2 Security Updater: Multiple vulnerabilities have been identified in IBM Cognos Controller

This bulletin addresses several security vulnerabilities. OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by IBM Cognos Controller. IBM Cognos Controller has addressed the applicable CVEs. There are multiple vulnerabilities in IBM® Runtime Environment Java™ Technology Edition, Version 7 and the IBM® Runtime Environment Java™ Technology Edition, Version 8 that are used by IBM Cognos Controller. These issues were disclosed as part of the IBM Java SDK updates in January 2017.

CVE(s): CVE-2017-3730, CVE-2017-3731, CVE-2017-3732, CVE-2016-7055, CVE-2017-3289, CVE-2017-3272, CVE-2017-3241, CVE-2016-5546, CVE-2017-3253, CVE-2016-5548, CVE-2016-5549, CVE-2017-3252, CVE-2016-5547, CVE-2016-5552, CVE-2017-3261, CVE-2017-3231, CVE-2017-3259, CVE-2016-2183

Affected product(s) and affected version(s):

IBM Cognos Controller 10.2.0

IBM Cognos Controller 10.2.1

IBM Cognos Controller 10.3.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2rVqXHa
X-Force Database: http://ift.tt/2kDB4yh
X-Force Database: http://ift.tt/2knsB3D
X-Force Database: http://ift.tt/2kDymIW
X-Force Database: http://ift.tt/2hjUUfe
X-Force Database: http://ift.tt/2lA6pnI
X-Force Database: http://ift.tt/2msIV19
X-Force Database: http://ift.tt/2lAcror
X-Force Database: http://ift.tt/2lA4akm
X-Force Database: http://ift.tt/2msWpdg
X-Force Database: http://ift.tt/2lAx183
X-Force Database: http://ift.tt/2msD77U
X-Force Database: http://ift.tt/2lAk4Lp
X-Force Database: http://ift.tt/2msBF5I
X-Force Database: http://ift.tt/2lAiqcB
X-Force Database: http://ift.tt/2msOwVj
X-Force Database: http://ift.tt/2lAc9xE
X-Force Database: http://ift.tt/2msIPqs
X-Force Database: http://ift.tt/2dR3VyC

The post IBM Security Bulletin: IBM Cognos Controller 2017Q2 Security Updater: Multiple vulnerabilities have been identified in IBM Cognos Controller appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2spZPnd