Vulnerability Bulletins |
IBM Security Bulletin: WebSphere DataPower XC10 Appliance does not provide a means of overwriting the SSD when an appliance is to be discarded ( CVE-2015-1970) |
|
| Affected software | IBM |
|
When the WebSphere DataPower XC10 Appliance is used, sometimes potentially sensitive data is written to the SDD card. When the box is discarded or redispositioned, a malicious person might gain access to this card, remove it from the appliance, and access the sensitive data. CVE(s): CVE-2015-1970 Affected product(s) and affected version(s): WebSphere DataPower XC10 Appliance V2.5 WebSphere DataPower XC10 Appliance V2.1 Refer to the following reference URLs for remediation and More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_websphere_datapower_xc10_appliance_does_not_provide_a_means_of_overwriting_the_ssd_when_an_appliance_is_to_be_discarded_cve_2015_1970?lang=en_us |
|






