Vulnerability Bulletins

IBM Security Bulletin: IBM Connections Mobile Server Security Refresh for Apache Struts CVE-ID: CVE-2015-5169 and CVE-2015-2992

   
Affected software IBM
 
This bulletin relates to security vulnerabilities that have been reported against Apache Struts through October 2015. The IBM Connections Mobile server uses a version of Struts that is vulnerable to these issues. Customers who use the IBM Connections mobile web client should apply this security refresh. CVE(s): CVE-2015-5169 and CVE-2015-2992 Affected product(s) and affected version(s): The following versions of IBM Connections are impacted: IBM Connections 5.0 IBM Connections 4.5 IBM

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_connections_mobile_server_security_refresh_for_apache_struts_cve_id_cve_2015_5169_and_cve_2015_2992?lang=en_us