Vulnerability Bulletins |
IBM Security Bulletin: IBM License Metric Tool v7.2.2 and v7.5 and IBM Tivoli Asset Discovery for Distributed v7.2.2 and v7.5 are vulnerable to Padding Oracle On Downgraded Legacy Encryption (POODLE) |
|
| Affected software | IBM |
|
TLS protocol support used in IBM License Metric Tool and IBM Tivoli Asset Discovery for Distributed is vulnerable to POODLE TLS attack (CVE-2014-8730). This attack enables a man-in-the-middle attacker to decrypt and intercept communications, including user-server and agent-server messages. CVE(s): CVE-2014-8730 Affected product(s) and affected version(s): IBM License Metric Tool 7.2.2 and 7.5 IBM Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 Refer to the following reference URLs More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_license_metric_tool_v7_2_2_and_v7_5_and_ibm_tivoli_asset_discovery_for_distributed_v7_2_2_and_v7_5_are_vulnerable_to_padding_oracle_on_downgraded_legacy_encryption_poodle |
|






