Security Bulletin
Summary
IBM WebSphere Application Server is shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise. Additionally, IBM Business Process Manager is shipped with IBM Cloud Orchestrator. The IBM SmartCloud Cost Management and IBM Tivoli Monitoring are shipped with Cloud Orchestrator Enterprise.
Information about a potential security vulnerability affecting IBM WebSphere Application Server, IBM SmartCloud Cost Management, IBM Business Process Manager, and Tivoli Monitoring are published in a security bulletin.
Note: IBM Cloud Orchestrator V2.4 FixPack 4 is not affected as it ships with IBM WebSphere Application Server V8.5.5.10.
Vulnerability Details
Consult the Security Bulletin: Vulnerability in Apache Standard Taglibs affects IBM WebSphere Application Server (CVE-2015-0254) for vulnerability details.
Affected Products and Versions
|
Principal Product and Version(s) | Affected Supporting Product and Version |
| IBM Cloud Orchestrator V2.5, V2.5.0.1, V2.5.0.2, V2.4, V2.4.01, V2.4.0.2, V2.4.0.3 |
|
| IBM Cloud Orchestrator V2.3, V2.3.0.1 through Interim Fix 9 |
|
| IBM Cloud Orchestrator Enterprise V2.5, V2.5.0.1, V2.5.0.2, V2.4, V2.4.01, V2.4.0.2, V2.4.0.3 |
|
| IBM Cloud Orchestrator Enterprise V2.3, V2.3.0.1 through Interim Fix 9 |
|
Remediation/Fixes
Refer to the following security bulletins for information about fixes addressed by IBM WebSphere Application Server and IBM Business Process Manager, which is shipped with IBM Cloud Orchestrator.
| Principal Product and Version(s) | Affected Supporting Product and Version | Affected Supporting Product Security Bulletin |
| IBM Cloud Orchestrator V2.5, V2.5.0.1, V2.5.0.2, V2.4, V2.4.01, V2.4.0.2,V2.4.0.3, |
| Security Bulletin: Vulnerability in Apache Standard Taglibs affects IBM WebSphere Application Server (CVE-2015-0254)
Security Bulletin: A Security vulnerability has been identified in IBM WebSphere Application Server shipped with IBM Business Process Manager, WebSphere Process Server and WebSphere Lombardi Edition (CVE-2015-0254) |
| IBM Cloud Orchestrator V2.3, V2.3.0.1 through Interim Fix 9 |
| Contact IBM Support |
Refer to the following security bulletins for information about fixes addressed by IBM WebSphere Application Server, IBM SmartCloud Cost Management, and Tivoli Monitoring, which are shipped with IBM Cloud Orchestrator Enterprise edition.
| Principal Product and Version(s) | Affected Supporting Product and Version | Affected Supporting Product Security Bulletin |
| IBM Cloud Orchestrator Enterprise V2.5, V2.5.0.1, V2.5.0.2, V2.4, V2.4.0.1, V2.4.0.2,V2.4.0.3 |
| Security Bulletin: Vulnerability in Apache Standard Taglibs affects IBM WebSphere Application Server (CVE-2015-0254) |
| Security Bulletin: IBM Tivoli Monitoring embedded WebSphere Application Server (CVE-2016-3426, CVE-2016-3427, CVE-2016-0306, CVE-2015-0254) | |
| IBM Cloud Orchestrator Enterprise V2.3, V2.3.0.1 through Interim Fix 9 |
| Contact IBM Support |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
30 November 2016: Original version published
03 February 2017: Update Tivoli Monitoring Version
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg2C1000225