IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM Process Designer used in IBM Business Automation Workflow, IBM Business Process Manager, and WebSphere Lombardi Edition
Oct 24, 2018 9:01 am EDT
Categorized: High Severity
Share this post:
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 6 and 7 used by IBM Process Designer. IBM Process Designer has addressed the applicable CVEs.
CVE(s): CVE-2018-1656, CVE-2018-12539
Affected product(s) and affected version(s):
This vulnerability affects IBM Business Automation Workflow V18.0.0.0 through V18.0.0.1, IBM Business Process Manager V7.5.0.0 through V8.6.0 2017.12, and WebSphere Lombardi Edition V7.2.0.0 through V7.2.0.5.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10731615
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144882
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148389
from IBM Product Security Incident Response Team https://ift.tt/2q89o8j