Vulnerability Bulletins

IBM Security Bulletin: Vulnerability reported in WebSphere Application Server management port affects IBM Emptoris Strategic Supply Management and IBM Emptoris Services Procurement (CVE-2015-1920)

   
Affected software IBM
 
The IBM Emptoris Strategic Supply Management Suite and IBM Emptoris Services Procurement products are affected by a vulnerability that exists in IBM WebSphere Application Server. The vulnerability could allow a remote attacker to execute arbitrary code by connecting to a management port and executing a specific sequence of instructions. CVE(s): CVE-2015-1920 Affected product(s) and affected version(s): IBM Emptoris Contract Management 9.5 through 10.0.4 IBM Emptoris Program Management

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_reported_in_websphere_application_server_management_port_affects_ibm_emptoris_strategic_supply_management_and_ibm_emptoris_services_procurement_cve_2015_1920?la