Vulnerability Bulletins

IBM Security Bulletin: TLS padding vulnerability affects IBM® DB2® LUW (CVE-2014-8730)

   
Affected software IBM
 
Transport Layer Security (TLS) padding vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) like attack affects IBM® DB2® LUW. CVE(s): CVE-2014-8730 Affected product(s) and affected version(s): Customers have Secure Sockets Layer (SSL) support enabled in their DB2 database system are affected. SSL support is not enabled in DB2 by default. All fix pack levels for IBM DB2 V9.5, V9.7, V10.1 and V10.5 editions listed below and running on AIX, Linux, HP, Solaris or

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_tls_padding_vulnerability_affects_ibm_db2_luw_cve_2014_8730?lang=en_us