Vulnerability Bulletins

IBM Security Bulletin: Java specific SLOTH - Weak MD5 Signature Hash

   
Affected software IBM
 
There is vulnerability in IBM® Runtime Environment Java™ Technology Edition, Versions 6, 7, and 8, that are used by FileNet Content Manager, IBM Content Foundation and FileNet BPM. These issues were disclosed as part of the IBM Java SDK updates in January 2016 and include the vulnerability commonly referred to as “SLOTH”. CVE(s): CVE-2015-7575Affected product(s) and affected version(s): FileNet Content Manager 5.1.0, 5.2.0, 5.2.1 IBM Content Foundation 5.2.0, 5.2.1

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_java_specific_sloth_weak_md5_signature_hash?lang=en_us