Vulnerability Bulletins

IBM Security Bulletin: IBM Connections Security Refresh (CVE-2014-0114, CVE-2014-0113, CVE-2014-0112, CVE-2014-0094, CVE-2014-0116 )

   
Affected software IBM
 
This bulletin relates to several security vulnerabilities that have been reported against Apache Struts through May 2014. IBM Connections uses a version of Struts that is vulnerable to these issues. CVE(s): CVE-2014-0116, CVE-2014-0114, CVE-2014-0113, CVE-2014-0094 and CVE-2014-0112 Affected product(s) and affected version(s): The following versions of IBM Connections are impacted: IBM Connections 5.0 IBM Connections 4.5 IBM Connections 4.0 IBM Connections 3.0.1.1 and earlier releases

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_connections_security_refresh_cve_2014_0114_cve_2014_0113_cve_2014_0112_cve_2014_0094_cve_2014_0116?lang=en_us