Vulnerability Bulletins |
IBM Security Bulletin: IBM WebSphere Application Server Liberty Profile vulnerability affects IBM Tivoli Application Dependency Discovery Manager (TADDM) (CVE-2015-2017) |
|
| Affected software | IBM |
|
WebSphere Application Server Liberty Profile that is embedded in TADDM could allow a remote attacker to has access to the customer app or a form which sends the contents in a header will be able to split the response and add headers to the response. The customer application will allow cross-site scripting, web cache poisoning, and other similar exploits. CVE(s): CVE-2015-2017Affected product(s) and affected version(s):TADDM 7.3.0.1-7.3.0.2 Refer to the following reference URLs for remediation More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_websphere_application_server_liberty_profile_vulnerability_affects_ibm_tivoli_application_dependency_discovery_manager_taddm_cve_2015_2017?lang=en_us |
|






