{"id":17404,"date":"2023-10-19T19:06:28","date_gmt":"2023-10-19T19:06:28","guid":{"rendered":"https:\/\/www.ibm.com\/community\/qradar\/?page_id=17404"},"modified":"2025-11-19T15:35:45","modified_gmt":"2025-11-19T15:35:45","slug":"security-bulletins","status":"publish","type":"page","link":"https:\/\/www.ibm.com\/community\/101\/cloudpaksystem\/security-bulletins\/","title":{"rendered":"IBM Cloud Pak System &#8211; 101 &#8211; Security Bulletins"},"content":{"rendered":"<p><!--Support Tools --><br \/>\n<!-- web components -->\n<link rel=\"stylesheet\" href=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/canary\/plex.css\"\/>\n<link rel=\"stylesheet\" href=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/canary\/grid.css\"\/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/accordion.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/button.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/checkbox.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/combo-box.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/content-switcher.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/data-table.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/floating-menu.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/form.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/input.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/link.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/list.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/loading.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/modal.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/multi-select.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/overflow-menu.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/pagination.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/progress-indicator.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/radio-button.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/search.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/select.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/skip-to-content.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/structured-list.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/tabs.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/tag.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/textarea.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/tile.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/toggle.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon\/web-components\/tag\/latest\/ui-shell.min.js\"><\/script><\/p>\n<p><!-- carbon for ibm.com -->\n<link rel=\"stylesheet\" href=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/table-of-contents.css\" \/>\n<link rel=\"stylesheet\" href=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/scroll-animations.css\" \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/card.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/card-group.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/button-group.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/search-with-typeahead.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/table-of-contents.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/leadspace.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/card-section-carousel.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/tag-group.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/link-list-section.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/video-player.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/carousel.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/scroll-animations.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/background-media.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/rtl\/link-with-icon.rtl.min.js\"><\/script><br \/>\n<script type=\"module\" src=\"https:\/\/1.www.s81c.com\/common\/carbon-for-ibm-dotcom\/tag\/v1\/latest\/content-block-horizontal.min.js\"><\/script><\/p>\n<p><!-- old js and css --><br \/>\n<script src=\"http:\/\/code.jquery.com\/jquery-1.11.3.min.js\"><\/script><br \/>\n<script src=\"https:\/\/nightly.datatables.net\/js\/jquery.dataTables.js\"><\/script><br \/>\n<script type=\"text\/javascript\" charset=\"utf8\" src=\"https:\/\/cdn.datatables.net\/responsive\/2.2.5\/js\/dataTables.responsive.min.js\"><\/script><br \/>\n<script type='text\/javascript' src='\/\/1.www.s81c.com\/common\/v18\/js\/tables.js' id='tables-js'><\/script>\n<link href=\"https:\/\/1.www.s81c.com\/common\/v18\/css\/tables.css\" rel=\"stylesheet\"\/>\n<p><!--------- header ---------><\/p>\n<div class=\"bx--grid bx--no-gutter\">\n    <dds-leadspace alt=\"alt text\" size=\"medium\">\n      <dds-leadspace-heading>IBM Cloud Pak System Security Bulletins<\/dds-leadspace-heading>\n      This page contains a searchable list of all IBM Cloud Pak System Security Bulletins. IBM Expert Lab consultants are the resource you can contact to help you secure your system. IBM product Support can<br \/>\n      help you find documents on current CVEs from when the product was shipped if you are unable to find them from this search.\n      <dds-background-media gradient-direction=\"left-to-right\" mobile-position=\"\" alt=\"Header image of tools and a library.\" default-src=\"https:\/\/www.ibm.com\/community\/101\/wp-content\/uploads\/sites\/5\/2019\/10\/Tools_101_Banner.png\">\n      <\/dds-background-media>\n    <\/dds-leadspace>\n<p><!--------- table ---------><\/p>\n<div id=\"datatable\" class=\"bx--row\" style=\"margin: 3rem 0;\">\n<div class=\"ibm-col-group ibm-col-full\">\n<div class=\"ibm-fluid ibm-fullwidth\">\n<table class=\"ibm-data-table ibm-padding-small\" data-scrollaxis=\"x\" data-info=\"true\" data-ordering=\"true\" data-paging=\"true\" data-searching=\"true\" data-widget=\"datatable\" id=\"tabledrop\">\n<caption><em>This list of technical support articles was updated on November 19, 2025.<\/em><\/caption>\n<form id=\"filter-bar\" class=\"ibm-row-form\" method=\"post\" action=\"__REPLACE_ME__\">\n<p class=\"ibm-form-elem-grp ibm-padding-top-1\">\n<p>      <span><\/p>\n<p>         <select class=\"dropdown-filter\"><option value=\"default\" selected disabled hidden>Filter by topic<\/option><option data-value=\"Install\">Install<\/option><option data-value=\"Upgrade\">Upgrade<\/option><option data-value=\"Must Gather\">Must Gather<\/option><option data-value=\"Error\">Error<\/option><option data-value=\"Settings\">Settings<\/option><\/select><\/p>\n<p>       <\/span><\/p>\n<p>       <button id=\"filter-bar\" class=\"search\" data-val=\"\">Clear<\/button><\/p>\n<\/form>\n<col width=\"100\">\n<col width=\"500\">\n<col width=\"500\">\n<thead>\n<tr>\n<th>Last Updated<\/th>\n<th>Title<\/th>\n<th>Abstract<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<p><!-- data-qradar=\"public\" --><\/p>\n<tr>\n<td>2025-11-11<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7237418\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in Open Source affect IBM Cloud Pak System<\/a><\/td>\n<td>Multiple vulnerabilities in Open Source affect IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-11-06<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7244117\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Due to the use of IBM Db2, IBM Cloud Pak System is affected by multiple vulnerabilities<\/a><\/td>\n<td>Vulnerabilities found in IBM Db2  LUW that affect  Foundation and IBM Tivoli Monitoring (ITM) pattern Types (pTypes)  shipped with IBM Cloud Pak System. Vulnerabilities were addressed in IBM Cloud Pak System.  IBM Cloud Pak System v2.3.6.0 has updated Foundation and ITM pTypes to Foundation version 2.1.28.1 and  ITM  version 1.0.29.1.  For all Db2 pTypes  is applicable IBM Db2 11.5.9 Special Build 58840.<\/td>\n<\/tr>\n<tr>\n<td>2025-11-06<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7246870\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Due to use of QOS.CH logback, IBM Cloud Pak System is affected by server-side request forgery and arbitrary code execution<\/a><\/td>\n<td>Due to use of  QOS.CH logback  IBM Cloud Pak System is affected by server-side request forgery and arbitrary code execution  [CVE-2024-12801, CVE-2024-12798].<\/td>\n<\/tr>\n<tr>\n<td>2025-09-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7245170\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple Vulnerabilities in VMware ESXi affect IBM Cloud Pak System<\/a><\/td>\n<td>Vulnerabilities in VMware ESXi affect IBM Cloud Pak System. IBM Cloud Pak System has addressed vulnerabilities. Cloud Pak Sytem has delivered updated workload nodes to VMware ESXi 83U3g.<\/td>\n<\/tr>\n<tr>\n<td>2025-09-16<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7245168\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae Java SDK affects WebSphere Application Server Pattern shipped with IBM Cloud Pak System<\/a><\/td>\n<td>IBM Cloud Pak System WebSphere Application Server Pattern (WAS pType) is vulnerable to multiple vulnerabilities in IBM SDK.<\/td>\n<\/tr>\n<tr>\n<td>2025-09-16<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7245075\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Due to the use of Google Go, IBM Cloud Pak Sys is affected by an infinite loop when unmarshaling certain forms of invalid JSON<\/a><\/td>\n<td>Vulnerability in Go used by Cloud Pak System [CVE-2024-24786].<\/td>\n<\/tr>\n<tr>\n<td>2025-08-20<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7241403\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Due to IBM Db2, IBM Cloud Pak System is affected by multiple vulnerabilities.<\/a><\/td>\n<td>IBM Db2 vulnerabilities have been found in IBM Cloud Pak System DB2 pattern type (db2 pType) shipped with Cloud Pak System. Vulnerabilities were addressed in IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7240236\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  IBM Cloud Pak System  is vulnerable to an authenticated command-execution due to use of VMWare vCenter [CVE-2025-41225].<\/a><\/td>\n<td>IBM Cloud Pak System  is vulnerable to an authenticated command-execution due to use of VMware vCenter [CVE-2025-41225].<\/td>\n<\/tr>\n<tr>\n<td>2025-07-28<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7240111\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in jackson-core affects IBM Cloud Pak System[CVE-2025-52999]<\/a><\/td>\n<td>Vulnerability found for potential stackoverflowError in jackson-core affects IBM Cloud Pak System.  Vulnerability was addressed by IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-24<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7240254\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:   Due to the use of IBM Tivoli Monitoring and IBM Db2, IBM Cloud Pak System  is affected by multiple vulnerabilities<\/a><\/td>\n<td>IBM Tivoli Monitoring code execution and IBM Db2 vulnerabilities have been found in IBM Tivoli Monitoring shipped  with IBM Cloud Pak System IBM Tivoli Monitoring(ITM) patternType (itm pType), and IBM Cloud Pak System DB2 pattern type (db2 pType) shipped with Cloud Pak System. Vulnerabilities were addressed in IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-22<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7240238\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  IBM Cloud Pak System  is vulnerable to an Improper Access Control due to use of Apache Commons BeanUtils  [CVE-2025-48734]<\/a><\/td>\n<td>Due to use of Apache Commons BeanUtils IBM Cloud Pak System  is vulnerable to an Improper Access Control.  IBM Cloud Pak System addressed vulnerability.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7239408\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Due to use of  Nodejs Express.js, multiple vulnerabilities affect IBM Cloud Pak System[CVE-2024-43796, CVE-2024-43799, CVE-2024-43800]<\/a><\/td>\n<td>Multiple vulnerabilities in Send cross-site scripting (XSS) within the SendStream.redirect(), serve-static built-in and response.redirect found in Node.js Express.js which is used by IBM Cloud Pak System.  Vulnerabilities were addressed by IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-11<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7239472\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Potential denial of service in X.509 name checks in OpenSSL affect Cloud Pak System [CVE-2024-6119]<\/a><\/td>\n<td>Potential denial of service in X.509 name checks in OpenSSL affect Cloud Pak System.  Vulnerability was addressed by IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-10<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7237420\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Due to use of IBM Tivoli Monitoring , IBM Cloud Pak System is affected by multiple vulnerabilities.<\/a><\/td>\n<td>Multiple vulnerabilities were addressed in IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-07-01<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7237138\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Due to use of IBM Storage Scale , IBM Cloud Pak System is affected by multiple vulnerabilities<\/a><\/td>\n<td>Multiple vulnerabilities  in IBM Storage Scale which could provide weaker than expected security were addressed in IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2025-06-30<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7231509\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK Java\u2122 affect IBM Cloud Pak System [CVE-2024-21144, CVE-2024-21131, CVE-2024-27267]<\/a><\/td>\n<td>Vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition affect IBM Cloud Pak System . These issues were disclosed as part of the IBM Java SDK updates in July 2024.<\/td>\n<\/tr>\n<tr>\n<td>2025-06-30<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7237164\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple Vulnerabilities in IBM Cloud Pak System[CVE-2020-5256, CVE-2025-2895]<\/a><\/td>\n<td>Multiple Vulnerabilities were addressed in IBM Cloud Pak System. IBM Cloud Pak System is affected to Prototype Pollution  due to Dojo and  HTML Injection in JavaScript.<\/td>\n<\/tr>\n<tr>\n<td>2025-06-30<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7185269\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Broadcomm VMware ESXi Vulnerabilities  affect IBM Cloud Pak System<\/a><\/td>\n<td>Broadcomm VMware ESXi Vulnerabilities  affect IBM Cloud Pak System[CVE-2025-22224, CVE-2025-22225,CVE-2025-22226]<\/td>\n<\/tr>\n<tr>\n<td>2025-06-27<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/7237162\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  IBM Cloud Pak System is vulnerable to HTML injection[CVE-2023-38007].<\/a><\/td>\n<td>IBM Cloud Pak System is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim&#39;s Web browser within the security context of the hosting site. Vulnerability was addressed in IBM Cloud Pak System.<\/td>\n<\/tr>\n<tr>\n<td>2019-05-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/883052\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in SNMP default community name for AIX affects IBM PureApplication System<\/a><\/td>\n<td>A vulnerability in SNMP default community name for AIX potentially impacts IBM PureApplication System. IBM PureApplication System has addressed the vulnerability with the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-10-17<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/728649\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in Samba affects IBM OS Image for Red Hat Linux Systems on IBM PureApplication (CVE-2018-1050)<\/a><\/td>\n<td>Samba is used by IBM OS Image for Red Hat Linux Systems on IBM PureApplication. The products that are identified for this support are:<br \/>\n&#8211; PureApplication System<br \/>\n&#8211; PureApplication Software<br \/>\n&#8211; PureApplication Service<\/p>\n<p>The following vulnerability has been addressed.<\/td>\n<\/tr>\n<tr>\n<td>2018-07-02<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715233\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK quarterly updates in January 2018. IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715241\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the OS Images for IBM PureApplication System. Java 7 is used by IBM Base OS images. These issues were disclosed as part of the IBM Java SDK updates in January 2018. IBM OS Image for Red Hat Linux Systems has addressed the following vulnerabilities.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715353\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments for IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the OS Images for IBM PureApplication System. Java 7 is used by IBM Base OS images. These issues were disclosed as part of the IBM Java SDK updates in April 2018. IBM OS Image for Red Hat Linux Systems has addressed the following vulnerabilities.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715349\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Security vulnerabilities in OpenSSL used by IBM PureApplication Systems ( CVE-2017-3737 CVE-2017-3738)<\/a><\/td>\n<td>OpenSSL, used by the IBM PureApplication System, has security vulnerabilities were disclosed by OpenSSL project.  The following vulnerabilities have been addressed.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-29<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715329\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: IBM Pure Application System is affected by a vulnerability in the GSKit component (CVE-2017-3736)<\/a><\/td>\n<td>There is a vulnerability in the GSKit component used by IBM Pure Application System.  The following vulnerability has been addressed.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-28<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/715351\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in April 2018 and the following vulnerabilities have been addressed.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/571005\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in WebSphere Application Server used by IBM PureApplication System (CVE-2017-12613)<\/a><\/td>\n<td>The Apache Portable Runtime (APR) could allow a remote attacker to obtain sensitive information or cause a denial of service. IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/569201\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK that affect IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the OS Images for IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in Oct 2017.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/569143\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source GNU glibc Vulnerabilities<\/p>\n<p>Security Bulletin: Open Source GNU glibc Vulnerabilities which is used by IBM OS Images for RedHat Linux in IBM PureApplication Systems (CVE-2017-12132)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source GNU glibc that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/569137\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Security vulnerability has been identified in IBM Spectrum Scale which is used by IBM PureApplication Systems\/Service (CVE-2017-1654)<\/a><\/td>\n<td>A security vulnerability has been identified in IBM Spectrum Scale that could allow a local user access to other users data in dump files.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/568659\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source OpenSSL Vulnerabilities which is used by IBM PureApplication Systems\/Service (CVE-2017-3736 CVE-2017-3738)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source OpenSSL that is used by the IBM PureApplication Systems\/Service<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/304703\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments.<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the OS Images for IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in Oct 2017.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/300665\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Open Source cURL Libcurl affects IBM PureApplication. (CVE-2017-1000257)<\/a><\/td>\n<td>Vulnerability in Open Source cURL Libcurl affects IBM PureApplication.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297761\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Network Time Protocol (NTP) vulnerability in AIX which is used by IBM OS Images in IBM PureApplication Systems (CVE-2016-9310)<\/a><\/td>\n<td>There are vulnerabilities in the Network Time Protocol (NTP)  in AIX that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297641\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source GNU glibc Vulnerabilities which is used by IBM OS Images for RedHat Linux in IBM PureApplication Systems (CVE-2014-9761 CVE-2015-8778 CVE-2015-8779)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source GNU glibc that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297535\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source Samba Samba Vulnerabilities which is used by IBM OS Images for RedHat Linux in IBM PureApplication Systems (CVE-2017-12163 CVE-2017-12150)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source Samba that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297627\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source Apache HTTP Server Vulnerabilities which is used by IBM PureApplication Systems (CVE-2017-7679 CVE-2017-3169 CVE-2017-3167)<\/a><\/td>\n<td>A vulnerability in Open Source Apache HTTP Server affects the PureSystems\u00ae Managers used by IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297537\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source Apache HTTP Server Vulnerabilities which is used by IBM PureApplication Systems (CVE-2016-0736 CVE-2016-2161 CVE-2016-8743)<\/a><\/td>\n<td>A vulnerability in Open Source Apache HTTP Server affects the PureSystems\u00ae Managers used by IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/297529\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: OpenSource GNU glibc Vulnerabilities which is used by IBM PureApplication Systems (CVE-2015-8776)<\/a><\/td>\n<td>A vulnerability in Open Source GNU glibc affects the PureSystems\u00ae Managers used by IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/296763\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source Apache HTTP Server Vulnerabilities which is used by IBM PureApplication Systems (CVE-2017-7668)<\/a><\/td>\n<td>A vulnerability in Open Source Apache HTTP Server affects the PureSystems\u00ae Managers used by IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/296601\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source GNU glibc Vulnerabilities which is used by IBM OS Images for RedHat Linux in IBM PureApplication Systems (CVE-2017-1000366)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source GNU glibc that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/295945\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication Systems<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in Jul 2017.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/567249\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Open Source Samba Samba Vulnerabilities which is used by IBM OS Images for RedHat Linux in IBM PureApplication Systems (CVE-2017-7494)<\/a><\/td>\n<td>There are vulnerabilities in the Open Source Samba that is used by the OS Images for IBM PureApplication Software Suite, IBM Bluemix Local System and IBM PureApplication System\/Software<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/566417\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments.<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, used by the OS Images for IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in Apr 2017.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/563501\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in April 2017. IBM PureApplication System has addressed the applicable CVEs.<br \/>\nThese issues were also addressed by IBM WebSphere Application Server shipped with IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/561643\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK, Java affect IBM PureApplication System<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in Jan 2017.  IBM PureApplication System has addressed the applicable CVEs.<br \/>\nThese issues were also addressed by IBM WebSphere Application Server shipped with IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/561641\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK, Java affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments.<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition used by IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments. These issues were disclosed as part of the IBM Java SDK updates in January 2017.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/561391\" target=\"_blank\" rel=\"noopener noreferrer\">Potential security vulnerability in WebSphere Application Server.  IBM WebSphere Application Server ships with IBM PureApplication System (CVE-2017-1137)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/561389\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: There is a potential cross-site request forgery in  IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2017-1194)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/294713\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Potential security vulnerability with IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2016-0360)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/294725\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Privilege escalation vulnerability with IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2017-1151)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/293231\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: There is a potential cross-site scripting vulnerability in the Admin Console of  IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2017-1121)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/291833\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in Brocade Network Advisor affect IBM PureApplication System.<\/a><\/td>\n<td>Brocade Network Advisor is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/290647\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Potential cross-site scripting in the Admin Console for IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2016-8934)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/290661\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Denial of Service with IBM WebSphere Application Server shipped with IBM PureApplication System (CVE-2016-8919)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/290639\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: There is a potential information disclosure in IBM WebSphere Application Server shipped with IBM PureApplication System using malformed SOAP requests on IBM WebSphere Application Server (CVE-2016-9736)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/289503\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK, Java\u2122 Technology Edition affect IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments. (CVE-2016-5573, CVE-2016-5542, and CVE-2016-5597)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK, Java\u2122 Technology Edition used by IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments.   These issues were disclosed as part of the IBM Java SDK updates in October 2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/289505\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM\u00ae Java\u2122 SDK affects IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments. (CVE-2016-3485)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition that is used by IBM OS Images for Red Hat Linux Systems, AIX-based, and Windows-based deployments.   This issue was disclosed as part of the IBM Java SDK updates in July 2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/289499\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM\u00ae Java\u2122 SDK affects IBM Image Construction and Composition Tool. (CVE-2016-3485)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition that is used by IBM Image Construction and Composition Tool. This issue was disclosed as part of the IBM Java SDK updates in July 2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/289287\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK, Java\u2122 Technology Edition affect IBM Image Construction and Composition Tool. (CVE-2016-5573, CVE-2016-5542, and CVE-2016-5597)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition that is used by IBM Image Construction and Composition Tool. These issues were disclosed as part of the IBM Java SDK updates in October 2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/289299\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool.<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on September 22 and 26, 2016 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/285615\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM PureApplication System.<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on September 22 and 26, 2016 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/285613\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM\u00ae SDK, Java\u2122 Technology Edition affect IBM PureApplication System. (CVE-2016-5542 and CVE-2016-5597)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition that is used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in October 2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/555465\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple security vulnerabilities have been identified in IBM WebSphere Application Server Liberty shipped with IBM PureApplication System<\/a><\/td>\n<td>IBM WebSphere Application Server Liberty is shipped as a component of IBM PureApplication System. Information about security vulnerabilities affecting IBM WebSphere Application Server Liberty have been published in security bulletins (CVE-2016-0378, CVE-2016-3040, CVE-2016-3042).<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/553679\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple security vulnerabilities have been identified in IBM WebSphere Application Server shipped with IBM PureApplication System<\/a><\/td>\n<td>IBM WebSphere Application Server  patterns are shipped as a component of IBM PureApplication System. Information about  security vulnerabilities affecting IBM WebSphere Application Server has been published in security bulletins (CVE-2016-0377, CVE-2016-0385, CVE-2016-2960, CVE-2016-0718, CVE-2016-3092, CVE-2016-5986, CVE-2016-5983, CVE-2016-3485).<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/549543\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by security vulnerabilities. (CVE-2016-2985 and CVE-2016-2984)<\/a><\/td>\n<td>A security vulnerability has been identified in all levels of IBM Spectrum Scale and IBM GPFS that could allow a local attacker to execute commands as root.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/549541\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2016-0392)<\/a><\/td>\n<td>A security vulnerability has been identified in all levels of IBM Spectrum Scale and IBM GPFS that could allow a local attacker to inject commands into setuid file parameters and execute commands as root.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/548199\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System. (CVE-2016-3426, and CVE-2016-0264)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in April  2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/548205\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Vulnerabilities in OpenSSL affect IBM PureApplication System. (CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/547903\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in Apache Struts has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2016-1181 and CVE-2016-1182)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/547889\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2016-0359)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/283789\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Open Source GNU glibc affects IBM OS Images for Red Hat Linux Systems. (CVE-2015-5277)<\/a><\/td>\n<td>A vulnerability in Open Source GNU glibc affects IBM OS Images for Red Hat Linux Systems.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/283291\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool (CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/282751\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM PureApplication System. (CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0702, and CVE-2016-0704)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/282723\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Vulnerabilities in OpenSSL affect IBM PureApplication System. (CVE-2016-0701, CVE-2015-3197)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on January 28, 2016 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/282079\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool. (CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0702, and CVE-2016-0704)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/282037\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool. (CVE-2016-0701, CVE-2015-3197)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on January 28, 2016 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/279761\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Image Construction and Composition Tool. (CVE-2016-0363, CVE-2016-0376, CVE-2016-3426, and CVE-2016-0264)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM Image Construction and Composition Tool. These issues were disclosed as part of the IBM Java SDK updates in April  2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/279767\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, IBM OS Images for AIX, and Windows. (CVE-2016-0363, CVE-2016-0376, CVE-2016-3426, and CVE-2016-0264)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows. These issues were disclosed as part of the IBM Java SDK updates in April  2016.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/280161\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Vulnerabilities in OpenSSL affect IBM PureApplication System. (CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794)<\/a><\/td>\n<td>Vulnerabilities in OpenSSL affect IBM PureApplication System. (CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794)<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/279121\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2016-0263)<\/a><\/td>\n<td>A security vulnerability has been identified in the current levels of IBM Spectrum Scale V4.2, V4.1 and IBM General Parallel File System V3.5, that could allow a local user, under special circumstances, to escalate their privileges or cause a denial of service when the mmapplypolicy command is issued with certain options and syntax.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/278661\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool. (CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/278651\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2015-7488)<\/a><\/td>\n<td>A security vulnerability has been identified in the current levels of IBM Spectrum Scale V4.1.1 thru 4.1.1.3 and V4.2.0.0 that could allow a local, unprivileged user or a user with network access to the IBM Spectrum Scale cluster, access to the LDAP directory bind user password when File protocol is deployed with LDAP \/ LDAP with Kerberos based authentication.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/278649\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2015-7456)<\/a><\/td>\n<td>A security vulnerability has been identified in the current levels of IBM Spectrum Scale V4.1.1 thru 4.1.1.3 and V4.2.0.0 that could allow a local unprivileged user, or a user with network access to the IBM Spectrum Scale cluster, to access admin passwords for object storage infrastructure. This vulnerability only affects clusters which have installed and deployed the Object protocol.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/278355\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2015-7403)<\/a><\/td>\n<td>A security vulnerability has been identified in the current levels of IBM Spectrum Scale V4.1.1, IBM GPFS V4.1 and V3.5 that could allow a local attacker to cause the node they are on to crash.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/277293\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2016-0306)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/277475\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in Samba \u2013including Badlock &#8211; affect IBM OS Images for Red Hat Linux Systems.<\/a><\/td>\n<td>Samba vulnerabilities were disclosed on April 12, 2016. Samba is used by IBM OS Images for Red Hat Linux Systems.  IBM OS Images for Red Hat Linux Systems has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/547311\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM Java SDK affects IBM OS Images for Red Hat Linux Systems, AIX, and Windows. (CVE-2015-4872)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows. The issue was disclosed as part of the IBM Java SDK updates in October 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/547309\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:A vulnerability in IBM Java SDK affects IBM Image Construction and Composition Tool. (CVE-2015-4872)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM Image Construction and Composition Tool.  The issue was disclosed as part of the IBM Java SDK updates in October 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/547307\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM Java SDK affects IBM PureApplication System. (CVE-2015-4872)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM PureApplication System. The issue was disclosed as part of the IBM Java SDK updates in October 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/544265\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2015-1788)<\/a><\/td>\n<td>An OpenSSL vulnerability has been identified in the current levels of IBM Spectrum Scale V4.1.1 and IBM GPFS V4.1.<\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/543835\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, IBM OS Images for AIX, and Windows. (CVE-2015-5041, CVE-2015-7575, CVE-2015-7981, CVE-2015-8126, CVE-2015-8472, and CVE-2015-8540)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows. These issues were disclosed as part of the IBM Java SDK updates in January 2016 and includes the vulnerability commonly referred to as \u201cSLOTH\u201d.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/543455\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM Java SDK affects IBM OS Images for Red Hat Linux Systems, AIX, and Windows. (CVE-2015-7575)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, IBM OS Images for AIX, and Windows. The issue was disclosed as part of the IBM Java SDK updates in January 2016 and this vulnerability is commonly referred to as \u201cSLOTH\u201d.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/543653\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A vulnerability in IBM Java SDK affects IBM PureApplication System. (CVE-2015-7575)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM PureApplication System. The issue was disclosed as part of the IBM Java SDK updates in January 2016 and this vulnerability is commonly referred to as \u201cSLOTH\u201d.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/543131\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:A vulnerability in IBM Java SDK affects IBM Image Construction and Composition Tool. (CVE-2015-7575)<\/a><\/td>\n<td>There is a vulnerability in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 and 7, that is used by IBM Image Construction and Composition Tool.  The issue was disclosed as part of the IBM Java SDK updates in January 2016 and this vulnerability is commonly referred to as \u201cSLOTH\u201d.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/541275\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2015-7417)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/539799\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM HTTP Server used by IBM WebSphere Application Server which is shipped with IBM PureApplication System  (CVE-2015-3183)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/539803\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2015-4938)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/538159\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:The GPFS pattern provided with IBM PureApplication System is affected by security vulnerabilities. (CVE-2015-4974 and CVE-2015-4981)<\/a><\/td>\n<td>Security vulnerabilities have been identified in the current levels of IBM Spectrum Scale V4.1.1, IBM GPFS V4.1 and V3.5:<br \/>\n&#8211; could allow a local non privileged attacker to execute commands with root privileges (CVE-2015-4974)<br \/>\n&#8211; could allow a local non privileged attacker to read system memory contents (CVE-2015-4981) <\/p>\n<p>IBM PureApplication System provides a GPFS pattern and addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/538147\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:Vulnerability in OpenSSL affects IBM PureApplication System. (CVE-2015-1788)<\/a><\/td>\n<td>An OpenSSL denial of service vulnerability disclosed by the OpenSSL Project affects GSKit.  IBM PureApplication System uses GSKit in user registry components in the Web application pattern type and GPFS pattern type.  IBM PureApplication System addressed the applicable CVE.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/537447\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2015-2017)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/537451\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:A security vulnerability has been identified in IBM HTTP Server used by IBM WebSphere Application Server which is shipped with IBM PureApplication System  (CVE-2015-1283)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/537461\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK including Logjam affect IBM PureApplication System. (CVE-2015-4000, CVE-2015-2613, CVE-2015-2601, CVE-2015-2625, and CVE-2015-1931)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in July 2015.<\/p>\n<p>This bulletin also addresses the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/537653\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:A security vulnerability has been identified in IBM HTTP Server used by IBM WebSphere Application Server which is shipped with IBM PureApplication System  (CVE-2015-4947)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/273159\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK including Logjam affect IBM Image Construction and Composition Tool. (CVE-2015-4000, CVE-2015-2613, CVE-2015-2601, CVE-2015-2625, and CVE-2015-1931)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM Image Construction and Composition Tool. These issues were disclosed as part of the IBM Java SDK updates in July 2015.<\/p>\n<p>This bulletin also addresses the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/273157\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL including Logjam affect IBM Image Construction and Composition Tool. (CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, and CVE-2015-4000)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on June 11, 2015 by the OpenSSL Project. This includes Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/273147\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX, and Windows. (CVE-2015-4000, CVE-2015-2613, CVE-2015-2601, CVE-2015-2625, and CVE-2015-1931)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows. These issues were disclosed as part of the IBM Java SDK updates in July 2015.<\/p>\n<p>This bulletin also addresses the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/272255\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM PureApplication System  (CVE-2015-7450)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a deployable component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/269989\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin:  Vulnerabilities in OpenSSL including Logjam affect IBM PureApplication System. (CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, and CVE-2015-4000)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on June 11, 2015 by the OpenSSL Project. This includes Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/269815\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Open Source GNU glibc affects IBM OS Images for Red Hat Linux Systems. (CVE-2013-7423)<\/a><\/td>\n<td>A vulnerability in Open Source GNU glibc affects IBM OS Images for Red Hat Linux Systems.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535743\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Security Vulnerability in IBM PureApplication System. (CVE-2015-1920)<\/a><\/td>\n<td>IBM PureApplication System contains IBM WebSphere Application Server, which has a security vulnerability that could allow a remote attacker to execute arbitrary code by connecting to a management port and executing a specific sequence of instructions.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535651\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Diffie-Hellman ciphers affects IBM PureApplication System. (CVE-2015-4000)<\/a><\/td>\n<td>The Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535401\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems, AIX, and Windows. (CVE-2015-2808, CVE-2015-0204, CVE-2015-1916, CVE-2015-0138)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows. These issues were disclosed as part of the IBM Java SDK updates in April 2015.  This bulletin also addresses FREAK: \u201cFactoring Attack on RSA-EXPORT keys&#34; SSL\/TLS vulnerability and RC4 Bar Mitzvah Attack for SSL\/TLS vulnerability.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535261\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Diffie-Hellman ciphers affects IBM Image Construction and CompositionTool. (CVE-2015-4000)<\/a><\/td>\n<td>The Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects IBM Image Construction and Composition Tool.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535645\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in Diffie-Hellman ciphers affects IBM OS Images for Red Hat Linux Systems, AIX, and Windows-based deployments.  (CVE-2015-4000)<\/a><\/td>\n<td>The Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol affects IBM OS Images for Red Hat Linux Systems, AIX, and Windows-based deployments.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/535253\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System. (CVE-2015-2808, CVE-2015-0204, CVE-2015-1916, and CVE-2015-0138)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM PureApplication System. These issues were disclosed as part of the IBM Java SDK updates in April 2015.  This bulletin also addresses FREAK: \u201cFactoring Attack on RSA-EXPORT keys&#34; SSL\/TLS vulnerability and RC4 Bar Mitzvah Attack for SSL\/TLS vulnerability.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/534687\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: IBM PureApplication System is affected by a security vulnerability. (CVE-2015-1890)<\/a><\/td>\n<td>A security vulnerability have been identified in the General Parallel File System gpfs.snap service tool that affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/533133\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Image Construction and Composition Tool (CVE-2015-2808, CVE-2015-1916, CVE-2015-0204, CVE-2015-0138)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and 7, that is used by IBM Image Construction and Composition Tool. These issues were disclosed as part of the IBM Java SDK updates in April 2015.  This bulletin also addresses FREAK: \u201cFactoring Attack on RSA-EXPORT keys&#34; SSL\/TLS vulnerability and RC4 Bar Mitzvah Attack for SSL\/TLS vulnerability.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/532815\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM OS Images for Red Hat Linux Systems and AIX (CVE-2015-0410 and CVE-2014-6593)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition Version 6 and 7 that are used by IBM OS Images for Red Hat Linux Systems and AIX.  These issues were disclosed as part of the IBM Java SDK updates in January 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/532535\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM PureApplication System (CVE-2015-0410 and CVE-2014-6593)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition Version 6 and 7 that are used by IBM PureApplication System.  These issues were disclosed as part of the IBM Java SDK updates in January 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/532531\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Image Construction and Composition Tool (CVE-2015-0410 and CVE-2014-6593)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition Version 6 and 7 that are used by IBM Image Construction and Composition Tool.  These issues were disclosed as part of the IBM Java SDK updates in January 2015.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/532489\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL (CVE-2014-3508 and CVE-2014-3509) affect the virtual machines deployed by IBM PureApplication System.<\/a><\/td>\n<td>Nine OpenSSL vulnerabilities were disclosed in August 2014.  This bulletin addresses the two vulnerabilities that are applicable to virtual machines which are deployed by IBM PureApplication System using the IBM OS Image for Red Hat Linux Systems and the IBM OS Image for AIX Systems.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/529997\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: TLS padding vulnerability affects IBM PureApplication System (CVE-2014-8730)<\/a><\/td>\n<td>Transport Layer Security (TLS) padding vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) like attack affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/529783\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affects IBM PureApplication System (CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292, and CVE-2015-0293)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on March 19, 2015 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System.  IBM PureApplication System has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/529785\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affects IBM Image Construction and Composition Tool (CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292, and CVE-2015-0293)<\/a><\/td>\n<td>OpenSSL vulnerabilities were disclosed on March 19, 2015 by the OpenSSL Project. OpenSSL is used by IBM Image Construction and Composition Tool.  IBM Image Construction and Composition Tool has addressed the applicable CVEs.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/529137\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in IBM Dojo Toolkit affect IBM Image Construction and Composition Tool (CVE-2014-8917)<\/a><\/td>\n<td>IBM Dojo Toolkit is vulnerable to cross-site scripting and affects IBM Image Construction and Composition Tool.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/265317\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Venom vulnerability affects IBM PureApplication System (CVE-2015-3456)<\/a><\/td>\n<td>IBM PureApplication System is vulnerable to Venom: &#34;Virtualized Environment Neglected Operation Manipulation&#34;.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/264737\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM Image Construction and Composition Tool (CVE-2014-3566 and CVE-2014-6457)<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition, Version 6 that is used by IBM PureApplication System.  This also includes a fix for the Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). These were disclosed as part of the IBM Java SDK updates in October 2014.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/262977\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in RC4 stream cipher affects IBM Image Construction and Composition Tool (CVE-2015-2808)<\/a><\/td>\n<td>The RC4 \u201cBar Mitzvah\u201d Attack for SSL\/TLS affects IBM Image Construction and Composition Tool.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/263031\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in RC4 stream cipher affects IBM PureApplication System (CVE-2015-2808)<\/a><\/td>\n<td>The RC4 \u201cBar Mitzvah\u201d Attack for SSL\/TLS affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/263029\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in RC4 stream cipher affects IBM OS Images for Red Hat Linux Systems and AIX. (CVE-2015-2808)<\/a><\/td>\n<td>The RC4 \u201cBar Mitzvah\u201d Attack for SSL\/TLS affects IBM OS Images for Red Hat Linux Systems and AIX.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/260267\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in IBM Java SDK affects IBM OS Images for Red Hat Linux Systems, AIX, and Windows. (CVE-2015-0138)<\/a><\/td>\n<td>The \u201cFREAK: Factoring Attack on RSA-EXPORT keys&#34; TLS\/SSL client and server vulnerability affects IBM SDK Java Technology Edition, Version 6 and IBM SDK Java Technology Edition, Version 7 that is used by IBM OS Images for Red Hat Linux Systems, AIX, and Windows.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/260161\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in IBM Java Runtime affects IBM Image Construction and Composition Tool (CVE-2015-0138)<\/a><\/td>\n<td>The \u201cFREAK: Factoring Attack on RSA-EXPORT keys&#34; TLS\/SSL client and server vulnerability affects IBM\u00ae Runtime Environment Java\u2122 Technology Edition, Version 6 that is used by IBM Image Construction and Composition Tool.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/259935\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM WebSphere Application Server Hypervisor Edition shipped with IBM PureApplication System (CVE-2015-0138)<\/a><\/td>\n<td>IBM WebSphere Application Server is shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM WebSphere Application Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/259271\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM PureApplication System (CVE-2014-3513, CVE-2014-3567, CVE-2014-3568)<\/a><\/td>\n<td>OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by IBM PureApplication System. IBM PureApplication System has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/259255\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Log viewer vulnerability affects IBM PureApplication System (CVE-2014-6190)<\/a><\/td>\n<td>Log viewer vulnerability affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/258619\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM Tivoli Directory Server and IBM Security Directory Server shipped with IBM PureApplication System. (CVE-2015-0138)<\/a><\/td>\n<td>IBM Tivoli Directory Server and IBM Security Directory Server are shipped as a component of IBM PureApplication System. Information about a security vulnerability affecting IBM Tivoli Directory Server and IBM Security Directory Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/257785\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in OpenSSL affect IBM Image Construction and Composition Tool (CVE-2014-3513, CVE-2014-3567, CVE-2014-3568)<\/a><\/td>\n<td>OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed by the OpenSSL Project on October 15, 2014. OpenSSL is used by IBM Image Construction and Composition Tool. IBM Image Construction and Composition Tool has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/256303\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerability in SSLv3 affects IBM PureApplication System (CVE-2014-3566)<\/a><\/td>\n<td>SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. SSLv3 is enabled in IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/526545\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: GNU C library (glibc) vulnerability affects IBM PureApplication System  (CVE-2015-0235)<\/a><\/td>\n<td>GNU C library (glibc) vulnerability that has been referred to as GHOST affects IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/523567\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: A security vulnerability has been identified in IBM HTTP Server shipped with IBM PureApplication System (CVE-2014-8730)<\/a><\/td>\n<td>IBM HTTP Server is shipped as a component that can be deployed as part of a virtual application pattern or virtual system. Information about a security vulnerability affecting IBM HTTP Server has been published in a security bulletin.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/522805\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: File path traversal vulnerabilities affect IBM PureApplication System  (CVE-2014-6158)<\/a><\/td>\n<td>File upload functionality within IBM PureApplication System might lead to server compromise and Denial of Service (DoS).<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/522615\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: SSLv3 POODLE attack vulnerability affects IBM Image Construction and Composition Tool (CVE-2014-3566)<\/a><\/td>\n<td>A vulnerability within IBM Image Construction and Composition Tool\u2019s usage of SSLv3 might allow a man-in-the-middle attacker to access the plain text of network traffic encrypted using SSLv3.  This vulnerability has been dubbed the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/252831\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: Vulnerabilities in Bash affect IBM PureApplication System  (CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, CVE-2014-6278)<\/a><\/td>\n<td>Six Bash vulnerabilities were disclosed in September 2014.  This bulletin addresses the vulnerabilities that have been referred to as \u201cBash Bug\u201d or \u201cShellshock\u201d and two memory corruption vulnerabilities.  Bash is used by IBM PureApplication System.<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/251931\" target=\"_blank\" rel=\"noopener noreferrer\">Security Bulletin: IBM PureApplication System &#8211; Proof of Concept exploit code, which uses a flaw in glibc that can allow a local unprivileged user to gain root on Linux machine<\/a><\/td>\n<td>Proof of Concept exploit code, which uses a flaw in glibc that can allow a local unprivileged user to gain root on a Linux machine. This affects virtual machines deployed by IBM PureApplication System using the IBM OS Image for RedHat Linux (version 2.0, 2.0.0.1, 2.0.0.2, 2.0.0.3, 2.0.0.4 and 2.1.0.0).<\/td>\n<\/tr>\n<tr>\n<td>2018-06-15<\/td>\n<td><a href=\"https:\/\/www.ibm.com\/support\/pages\/node\/251051\" target=\"_blank\" rel=\"noopener noreferrer\">IBM Pure Application System &#8211; Java SE issues disclosed in the Oracle July 2014 Critical Patch Update, plus 1 additional vulnerability<\/a><\/td>\n<td>There are multiple vulnerabilities in IBM\u00ae SDK Java\u2122 Technology Edition that is shipped with IBM Pure Application System. These issues were disclosed as part of the IBM Java SDK updates in July 2014.<\/td>\n<\/tr>\n<p><!-- end data-qradar=\"public\" --><\/p>\n<\/tbody>\n<\/table>\n<\/dds-content-item-horizontal-media>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><!-------Footer Section----------><\/p>\n<div class=\"item-horizontal-with-media\" style=\"background-color: #f4f4f4;margin-bottom: -0.6%;\">\n<div>\n<hr class=\"bx--hr\">\n    <\/div>\n<div id=\"tn\" class=\"bx--row\" style=\"margin: 2rem 0;\">\n<div class=\"bx--col-sm-16 bx--col-lg-4\"style=\"margin-top: 15px\">\n            <dds-image alt=\"image\" slot=\"media\"\n            default-src=\"https:\/\/www.ibm.com\/community\/101\/wp-content\/uploads\/sites\/5\/2024\/02\/IBM_Security_lockup_color_rev_RGB_Black-Small-e1707158165672.png\"\n            alt=\"\" width=\"300\" height=\"95\" class=\"alignnone size-medium wp-image-3083\" data-autoid=\"dds--image\"\n            style=\"width: 100%; margin: auto;\">\n        <\/dds-image>\n        <\/div>\n<div class=\"bx--col-sm-4 bx--col-lg-8\" style=\"margin-top: 4%;\" align=\"center\">\n<p class=\"ibm-h4 ibm-small\"><em><span class=\"ibm-pull-quote-open ibm-textcolor-blue-50\">&#8220;<\/span>IBM<br \/>\n                    prides itself on delivering world class software support with highly skilled, customer-focused<br \/>\n                    people.<br \/>\n                    <span class=\"ibm-pull-quote-close ibm-textcolor-blue-50\">&#8221;<\/span><\/em><\/p>\n<div class=\"bx--col-sm-16 bx--col-lg-8\">\n                 \n                <dds-button-group slot=\"action\">\n                    <dds-button-group-item target=\"_blank\" href=\"https:\/\/www.ibm.com\/community\/101\/\">\n                        Return to 101 home\n                    <\/dds-button-group-item>\n                <\/dds-button-group>\n            <\/div>\n<\/p><\/div>\n<div class=\"bx--col-sm-16 bx--col-lg-4\" style=\"margin-top: 2%;\">\n            <dds-link-list slot=\"footer\" type=\"vertical\" data-autoid=\"dds--link-list\">\n                <dds-content-item-heading role=\"heading\" aria-level=\"4\" data-autoid=\"dds--content-item__heading\"\n                    slot=\"heading\" style=\"margin-top: 1px;\">Contact<br \/>\n                    Support <\/dds-content-item-heading>\n                <dds-content-item-paragraph data-autoid=\"dds--content-item-paragraph\"> Find your regional<br \/>\n                    support contact\n                <\/dds-content-item-paragraph>\n<section role=\"region\" id=\"policy\">\n<div style=\"margin-left: -3%;\">\n<div class=\"\"\n                            data-widget=\"setsameheight\" data-always=\"true\" data-excludesmallgrid=\"true\"\n                            data-items=\".ibm-card .ibm-blocklink\"><\/p>\n<div id=\"langDropdown\" class=\"ibm-col-16-16\"><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<\/dds-link-list>\n        <\/div>\n<\/p><\/div>\n<hr class=\"bx--hr\">\n<\/div>\n<\/dds-content-item-horizontal-media>\n<!---------- End Footer---------><br \/>\n<!--feedback--><\/p>\n<div class=\"fbCont ibm-btn-systems-blue-6\" onclick=\"feedBack.showFb()\">\n<div>\n<p class=\"ibm-textcolor-white-core\">Give Feedback<\/p>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>IBM Cloud Pak System Security Bulletins This page contains a searchable list of all IBM Cloud Pak System Security Bulletins. IBM Expert Lab consultants are the resource you can contact to help you secure your system. IBM product Support can help you find documents on current CVEs from when the product was shipped if you [&hellip;]<\/p>\n","protected":false},"author":56819,"featured_media":0,"parent":16787,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-brochureware.php","meta":{"footnotes":""},"tags":[],"_links":{"self":[{"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/pages\/17404"}],"collection":[{"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/users\/56819"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/comments?post=17404"}],"version-history":[{"count":80,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/pages\/17404\/revisions"}],"predecessor-version":[{"id":24140,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/pages\/17404\/revisions\/24140"}],"up":[{"embeddable":true,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/pages\/16787"}],"wp:attachment":[{"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/media?parent=17404"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ibm.com\/community\/101\/wp-json\/wp\/v2\/tags?post=17404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}