Apache Software Foundation Affected

Updated:  November 10, 2015

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Cisco Affected

Updated:  July 18, 2017

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

Cisco has released a security advisory and list of affected products at the URL below. Cisco has assigned CVE-2015-6420 to this issue.

Vendor References

Addendum

As of 2017-07-18, CERT/CC is aware of a report that Cisco Unity Express (CUE) 8.6.1 is still vulnerable to this issue and is incorrectly identified as "not vulnerable" in the above Cisco advisory. We have reached out to Cisco for clarification.

IBM Corporation Affected

Updated:  November 30, 2015

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

IBM has released a security advisory for WebSphere at the following URL:

Vendor References

Jenkins Affected

Updated:  November 30, 2015

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

Jenkins has released a security advisory at the URL below. CVE-2015-8103 was assigned this issue in Jenkins.

Vendor References

Oracle Corporation Affected

Updated:  November 30, 2015

Status

Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

Oracle has released a security advisory at the URL below:

Vendor References

Red Hat, Inc. Unknown

Updated:  November 30, 2015

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

JBOSS has been reported as being affected.

Unify Inc Affected

Updated:  November 30, 2015

Statement Date:   November 24, 2015

Status

Affected

Vendor Statement

"Unify is affected in two product lines as listed below. For details refer to the information given in the Security Advisory OBSO-1511-01. We recommend all customers to apply the mitigations described in the advisory and install the corresponding product fix releases as soon as available. To get notified about Advisory updates, subscribe as listed in https://www.unify.com/security/advisories."

Vendor Information

Unify has issued Security Advisory OBSO-1511-01 at the URL listed below. Mitre had assigned two CVE IDs for Unify products impacted by VU#576313: CVE-2015-8237, affected products: Unify OpenScape Fault Management V7 ("cpe:/a:unify:openscape_fault_management:7.%02") Unify OpenScape Fault Management V8 ("cpe:/a:unify:openscape_fault_management:8.%02") CVE-2015-8238, affected products: Unify OpenScape UC Application V7 ("cpe:/a:unify:openscape_uc_application:7.%02") Unify OpenScape Common Management Platform V7 ("cpe:/a:unify:openscape_common_management_platform:7.%02")

Vendor References