Vulnerability Bulletins

IBM SDK, Java Technology Edition fixes to mitigate against the POODLE security vulnerability (CVE-2014-3556)

   
Affected software IBM
 
Fixes are provided with the latest refreshes of the IBM SDK, Java Technology Edition to mitigate against the Padding Oracle On Downgraded Legacy Encryption (POODLE) vulnerability on Secure Socket Layer (SSL) V3.0. In order to mitigate this vulnerability, the SSL V3.0 protocol must not be enabled. The IBM SDK has been updated to disable SSL V3.0 automatically. These fixes implement a significant change in default behavior that will cause failures in any applications that rely exclusively on SSL

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_sdk_java_technology_edition_fixes_to_mitigate_against_the_poodle_security_vulnerability_cve_2014_3556?lang=en_us