Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in Network Time Protocol(NTP) affect WebSphere DataPower XC10 Appliance (CVE-2016-5300, CVE-2015-7704, CVE-2015-8138)

   
Affected software IBM
 
There are multiple vulnerabilities in Network Time Protocol(NTP) implementation that is used by WebSphere DataPower XC10 Appliance. These vulnerabilities addressed include the ability to disable the NTP client and bypass security restrictions to bypass the timestamp validation check.CVE(s): CVE-2015-5300, CVE-2015-7704, CVE-2015-8138Affected product(s) and affected version(s):WebSphere DataPower XC10 Appliance Version 2.1 WebSphere DataPower XC10 Appliance Version 2.5 Refer to the following

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_network_time_protocol_ntp_affect_websphere_datapower_xc10_appliance_cve_2016_5300_cve_2015_7704_cve_2015_8138?lang=en_us