Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in FasterXML jackson-databind

IBM Watson Discovery for IBM Cloud Pak for Data ships with versions of FasterXML jackson-databind vulnerable to serialization gadgets.

Affected product(s) and affected version(s):

Affected Product(s)Version(s)
ICP – Discovery2.0.0-2.0.1

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1126359

The post Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in FasterXML jackson-databind appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/358zYkJ