IBM Security Bulletin: Multiple security vulnerabilities affect IBM WebSphere Application Server in IBM Cloud (CVE-2017-1681, CVE-2016-1000031)

There is a potential information disclosure vulnerability in WebSphere Application Server. There is a potential vulnerability in the Apache Commons FileUpload used by WebSphere Application Server traditional and WebSphere Application Server Liberty.

CVE(s): CVE-2017-1681, CVE-2016-1000031

Affected product(s) and affected version(s):

This vulnerability affects the following versions and releases of IBM WebSphere Application Server:
Liberty
Version 9.0
Version 8.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg22013359
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/134003
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/117957

The post IBM Security Bulletin: Multiple security vulnerabilities affect IBM WebSphere Application Server in IBM Cloud (CVE-2017-1681, CVE-2016-1000031) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2Gfc4Hj