Vulnerability Bulletins

IBM Security Bulletin: IBM License Metric Tool v7.2.2 and v7.5 and IBM Tivoli Asset Discovery for Distributed v7.2.2 and v7.5 are vulnerable to Padding Oracle On Downgraded Legacy Encryption (POODLE)

   
Affected software IBM
 
TLS protocol support used in IBM License Metric Tool and IBM Tivoli Asset Discovery for Distributed is vulnerable to POODLE TLS attack (CVE-2014-8730). This attack enables a man-in-the-middle attacker to decrypt and intercept communications, including user-server and agent-server messages. CVE(s): CVE-2014-8730 Affected product(s) and affected version(s): IBM License Metric Tool 7.2.2 and 7.5 IBM Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 Refer to the following reference URLs

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_license_metric_tool_v7_2_2_and_v7_5_and_ibm_tivoli_asset_discovery_for_distributed_v7_2_2_and_v7_5_are_vulnerable_to_padding_oracle_on_downgraded_legacy_encryption_poodle