Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in Apache Groovy that could affect IBM Development Package for Apache Spark (CVE-2015-3253)

   
Affected software IBM
 
Apache Groovy™ could allow a remote attacker to run arbitrary, untrusted code on the system.CVE(s): CVE-2015-3253Affected product(s) and affected version(s):IBM® Development Package for Apache Spark™ v1.5.2.x, v1.6.0.x, and v1.6.1.x These depend upon a version of Groovy, prior to Apache Groovy v2.4.4, that is affected by this vulnerability.Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin:

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerability-in-apache-groovy-that-could-affect-ibm-development-package-for-apache-spark-cve-2015-3253/