Vulnerability Bulletins

IBM Security Bulletin: IBM WebSphere Application Server Liberty Profile vulnerability affects IBM Tivoli Application Dependency Discovery Manager (TADDM) (CVE-2015-2017)

   
Affected software IBM
 
WebSphere Application Server Liberty Profile that is embedded in TADDM could allow a remote attacker to has access to the customer app or a form which sends the contents in a header will be able to split the response and add headers to the response. The customer application will allow cross-site scripting, web cache poisoning, and other similar exploits. CVE(s): CVE-2015-2017Affected product(s) and affected version(s):TADDM 7.3.0.1-7.3.0.2 Refer to the following reference URLs for remediation

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_websphere_application_server_liberty_profile_vulnerability_affects_ibm_tivoli_application_dependency_discovery_manager_taddm_cve_2015_2017?lang=en_us