IBM published two Security Bulletins that affect the current app-backup/tsm-8.1.17.2 in the tree: https://www.ibm.com/support/pages/node/7037816 This is CVE-2018-11087 and effects the bundled amqp-client jar file https://www.ibm.com/support/pages/node/7037814 This one doesn't have a CVEID but the "IBM X-Force ID" 177835 and effects the bundled commons-codec jar file. Reproducible: Always The vulnerabilities are fixed in version 8.1.20.0
Created attachment 875501 [details] tsm-8.1.20.0.ebuild I created this ebuild in my local overlay and installed it on my servers.
Thanks for reporting! Dropping version from the summary while there's no fixed version in tree.
commit c16a53958a2594c747803fd4554550b4bfbb3842 Author: Florian Schmaus <flow@gentoo.org> Date: Sat Apr 27 16:46:12 2024 +0200 app-backup/tsm: add 8.1.22.0 As requested by dilfridge in #-dev. Signed-off-by: Florian Schmaus <flow@gentoo.org>
Stabilized and cleanup done