Vulnerability Bulletins

Apache Commons Vulnerability for handling Java object deserialization

   
Affected software IBM
 
On November 6, 2015 a remote execution vulnerability that affects multiple releases of Apache Commons Collections, was published by Foxglove Security Group. IBM is analyzing its products to determine which ones may be affected by this vulnerability. Affected IBM products will be issuing mitigations and/or fixes as soon as possible. IBM has provided a fix for the IBM WebSphere Application server. Please actively monitor both your IBM Support Portal for available fixes and this blog for

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/apachecommons?lang=en_us