Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in Apache Standard Taglibs affects Liberty for Java for IBM Bluemix (CVE-2015-0254)

   
Software afectado IBM
 
There is an XML External Entity Injection (XXE) vulnerability in the Apache Standard Taglibs that affects IBM WebSphere Application Server.CVE(s): CVE-2015-0254Affected product(s) and affected version(s):This vulnerability affects all versions of Liberty for Java in IBM Bluemix up to and including v2.9.Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21985531X-Force Database:

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerability-in-apache-standard-taglibs-affects-liberty-for-java-for-ibm-bluemix-cve-2015-0254/