Vulnerability Bulletins

IBM Security Bulletin: Various IBM WebSphere MQ Installers are susceptible to DLL-planting vulnerabilities (CVE-2016-2542 & CVE-2016-4560)

   
Affected software IBM
 
Various IBM WebSphere MQ graphical user interface installers are susceptible to a DLL-planting vulnerability where a malicious DLL, that is present in the Windows search path, could be loaded by the operating system in place of the genuine file. The vulnerability affects Windows executable installers downloaded from IBM prior to 2nd June 2016.CVE(s): CVE-2016-2542, CVE-2016-4560Affected product(s) and affected version(s):The vulnerability affects the executable (.exe file extension) installers,

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-various-ibm-websphere-mq-installers-are-susceptible-to-dll-planting-vulnerabilities-cve-2016-2542-cve-2016-4560/