May 30, 2019 9:01 am EDT
Categorized: High Severity
Share this post:
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Versions 6 and 7 used by the desktop version of IBM Process Designer. IBM Process Designer has addressed the applicable CVEs.
CVE(s): CVE-2019-2602, CVE-2019-2684
Affected product(s) and affected version(s):IBM Business Automation Workflow 18.0.0.1, 18.0.0.2, 19.0.0.1IBM Business Process Manager 8.6.0.0 – 8.6.0.0 CF2018.03IBM Business Process Manager 8.5.7 – 8.5.7 CF2017.06IBM Business Process Manager 8.5.6.0 – 8.5.6.0 CF02IBM Business Process Manager 8.5.5.0IBM Business Process Manager 8.5.0.0 – 8.5.0.2IBM Business Process Manager 8.0.0.0 – 8.0.1.3IBM Business Process Manager 7.5.0.0 – 7.5.1.2
Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10884048X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/159698X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/159776
Support the originator by clicking the read the rest link below.