Vulnerability Bulletins

IBM Security Bulletin: WebSphere DataPower XC10 Appliance does not provide a means of overwriting the SSD when an appliance is to be discarded ( CVE-2015-1970)

   
Affected software IBM
 
When the WebSphere DataPower XC10 Appliance is used, sometimes potentially sensitive data is written to the SDD card. When the box is discarded or redispositioned, a malicious person might gain access to this card, remove it from the appliance, and access the sensitive data. CVE(s): CVE-2015-1970 Affected product(s) and affected version(s): WebSphere DataPower XC10 Appliance V2.5 WebSphere DataPower XC10 Appliance V2.1 Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_websphere_datapower_xc10_appliance_does_not_provide_a_means_of_overwriting_the_ssd_when_an_appliance_is_to_be_discarded_cve_2015_1970?lang=en_us