IBM Security Bulletin: Vulnerability in Apache Tomcat affects IBM Algo One – Algo Risk Application (CVE-2017-5648)

IBM Algo One – Algo Risk Application could allow a remote attacker to bypass security restrictions, caused by the failure to use the appropriate facade object by certain application listener calls. (Advsory 8335)

CVE(s): CVE-2017-5648

Affected product(s) and affected version(s):

Algo One – Algo Risk Application (ARA) versions 5.1.0, 5.0.0, 4.9.1.

Apache Tomcat is not packaged with Algo One – Algo Risk Application 5.1.0.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2zPzqDw
X-Force Database:

The post IBM Security Bulletin: Vulnerability in Apache Tomcat affects IBM Algo One – Algo Risk Application (CVE-2017-5648) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2hB1M9S