Vulnerability Bulletins |
IBM Security Bulletin: Current Releases of IBM® SDK for Node.js™ in IBM Bluemix are affected by CVE-2016-3956, CVE-2016-2515 and CVE-2016-2537. |
|
| Affected software | IBM |
|
IBM SDK for Node.js in IBM Bluemix are affected by a HTTP bearer token leak in the npm package management tool and two denial of service vulnerabilities in modules used by the npm package management tool.CVE(s): CVE-2016-3956, CVE-2016-2515, CVE-2016-2537Affected product(s) and affected version(s):These vulnerabilities affect all versions up to and including IBM SDK for Node.js v1.1.0.20 and v1.2.0.10 and v4.4.1.0 corresponding to open-source version v0.10.42, v0.12.12 and v4.4.1, respectively. More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_current_releases_of_ibm_sdk_for_node_js_in_ibm_bluemix_are_affected_by_cve_2016_3956_cve_2016_2515_and_cve_2016_2537?lang=en_us |
|






