IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor
Security vulnerabilities have been reported for IBM SDK for Node.js. IBM Business Process Manager includes a stand-alone tool for editing configuration properties files that is based IBM SDK for Node.js.
CVE(s): CVE-2017-1000381, CVE-2017-11499
Affected product(s) and affected version(s):
- IBM Business Process Manager V8.5.5.0 – V8.5.7.0 including cumulative fix 2017.06
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2xtkjxS
X-Force Database: http://ift.tt/2h8Xc5H
X-Force Database: http://ift.tt/2h8Xb1D
The post IBM Security Bulletin: Security vulnerabilities in IBM SDK for Node.js might affect IBM Business Process Manager (BPM) Configuration Editor appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2wM3U3Y