IBM Security Bulletin: Potential Remote code execution vulnerability in WebSphere Application Server affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2018-1904)

There is a potential remote code execution vulnerability in WebSphere Application Server which affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center).

CVE(s): CVE-2018-1904

Affected product(s) and affected version(s):

The versions listed above apply to all licensed offerings of IBM Spectrum Control.

Note that 5.3 versions of IBM Spectrum Control are not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10793725
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152533

The post IBM Security Bulletin: Potential Remote code execution vulnerability in WebSphere Application Server affects IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2018-1904) appeared first on IBM PSIRT Blog.

Affected ProductAffected Versions
IBM Tivoli Storage Productivity Center5.2.0 – 5.2.7.1
IBM Spectrum Control5.2.8 – 5.2.13


from IBM Product Security Incident Response Team https://ibm.co/2TI24gw