Security Bulletin: An Apache Commons Compress vulnerability has been identified with the embedded IBM FileNet P8 Content Platform Engine component in IBM Business Process Manager and IBM Business Automation Workflow
An Apache Commons Compress vulnerability has been identified with the embeded IBM FileNet P8 Content Platform Engine component, specifically with the Administration Console for Content Platform Engine application, in IBM Business Process Manager and IBM Business Automation Workflow.
Affected product(s) and affected version(s):
Affected Product(s) | Version(s) |
IBM Business Process Manager | 8.5.7 |
IBM Business Automation Workflow | 18.0.0.0 |
IBM Business Automation Workflow | 18.0.0.1 |
Note: CVE 2019-12402, which is specifically for an IBM Administration Console for Content Platform Engine that is part of the embedded Content Platform Engine, does not affect Business Automation Workflow V18.0.0.2 or later versions.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www.ibm.com/support/pages/node/1283920
The post Security Bulletin: An Apache Commons Compress vulnerability has been identified with the embedded IBM FileNet P8 Content Platform Engine component in IBM Business Process Manager and IBM Business Automation Workflow appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/311pjXr