Vulnerability Bulletins

IBM Security Bulletin: Security vulnerability in Node.js module affects IBM Business Process Manager (BPM) Configuration Editor (CVE-2015-1164)

   
Affected software IBM
 
A security vulnerability has been reported for a dependent Node.js module "express". CVE-2015-1164 affects IBM Business Process Manager (BPM) because IBM BPM includes a stand-alone tool for editing configuration properties files that is based on open source Node.js technology. CVE(s): CVE-2015-1164 Affected product(s) and affected version(s): IBM Business Process Manager Express V8.5.5 IBM Business Process Manager Standard V8.5.5 IBM Business Process Manager Advanced V8.5.5

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_security_vulnerability_in_node_js_module_affects_ibm_business_process_manager_bpm_configuration_editor_cve_2015_1164?lang=en_us