Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere DataPower XC10 Appliance (CVE-2016-0475, CVE-2015-7575, CVE-2016-0448)

   
Affected software IBM
 
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Technology Edition, Versions 6 and 7 that are used by WebSphere DataPower XC10 Appliance. These issues were disclosed as part of the IBM Java SDK updates in January 2016 and includes the vulnerability commonly referred to as “SLOTH”. CVE(s): CVE-2016-0475, CVE-2015-7575 and CVE-2016-0448Affected product(s) and affected version(s):WebSphere DataPower XC10 Appliance Version 2.1 WebSphere DataPower XC10

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_java_runtime_affect_websphere_datapower_xc10_appliance_cve_2016_0475_cve_2015_7575_cve_2016_0448?lang=en_us