Vulnerability Bulletins

IBM Security Bulletin: Current Releases of IBM® SDK for Node.js™ are affected by CVE-2016-2515 and CVE-2016-2537

   
Affected software IBM
 
Two denial of service vulnerabilities in modules used by the npm package management tool CVE(s): CVE-2016-2515 and CVE-2016-2537Affected product(s) and affected version(s):These vulnerabilities affect IBM SDK for Node.js v1.1.0.20 and previous releases. These vulnerabilities affect IBM SDK for Node.js v1.2.0.9 and previous releases. These vulnerabilities affect IBM SDK for Node.js v4.3.2.0 and previous releases. Refer to the following reference URLs for remediation and additional vulnerability

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_current_releases_of_ibm_sdk_for_node_js_are_affected_by_cve_2016_2515_and_cve_2016_2537?lang=en_us