Vulnerability Bulletins

IBM Security Bulletin: Multiple security vulnerabilities affect IBM WebSphere Application Server for Bluemix

   
Affected software IBM
 
There is an XML External Entity Injection (XXE) vulnerability in the Apache Standard Taglibs that affects IBM WebSphere Application Server. There is a potential for weaker than expected security when using the WebSphere Application Server Liberty profile API Discovery feature and Swagger documents. There is a potential information disclosure vulnerability in Admin Center for IBM WebSphere Application Server Liberty. There is a potential HTTP response splitting vulnerability in IBM WebSphere

More info:

https://www.ibm.com/blogs/psirt/ibm-check-out-the-new-support-experience-beta-14/