Lucene search

K
ibmIBMB8D7C45A7B91FC54907F2A1A1E6B04BDAFBFDF653C7180AD40F4BA7A5091A75B
HistoryJun 17, 2018 - 3:23 p.m.

Security Bulletin: Multiple security vulnerabilities have been identified in WebSphere Application Server shipped with IBM Tivoli System Automation Application Manager (CVE-2016-3426, CVE-2016-3427)

2018-06-1715:23:06
www.ibm.com
18

EPSS

0.495

Percentile

97.5%

Summary

WebSphere Application Server is shipped as a component of IBM Tivoli System Automation Application Manager. Information about a security vulnerability affecting WebSphere Application Server has been published in a security bulletin.

Vulnerability Details

Consult the security bulletin “Security Bulletin: Multiple vulnerabilities in IBM® Java SDK affect WebSphere Application Server April 2016 CPU (CVE-2016-3426, CVE-2016-3427)” for further vulnerability details and information about fixes.

Affected Products and Versions

Principal Product and Version(s)

| Affected Supporting Product and Version
—|—
IBM Tivoli System Automation Application Manager 4.1| WebSphere Application Server 8.5
Note that IBM Tivoli System Automation Application Manager 3.2.2, 3.2.1, and 3.2.0 are not affected.

Remediation/Fixes

You need to install the corresponding APAR from WebSphere Application Server. Please follow the instructions on this link: http://www.ibm.com/support/docview.wss?uid=swg21982223. Please see section “Affected Products and Versions” in this bulletin on details which fix of WebSphere Application Server applies to your version of IBM Tivoli System Automation Application Manager.

Workarounds and Mitigations

None.