Vulnerability Bulletins

IBM Security Bulletin: SSLv3 POODLE attack vulnerability affects IBM Image Construction and Composition Tool (CVE-2014-3566)

   
Affected software IBM
 
A vulnerability within IBM Image Construction and Composition Tool’s usage of SSLv3 might allow a man-in-the-middle attacker to access the plain text of network traffic encrypted using SSLv3. This vulnerability has been dubbed the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. CVE(s): CVE-2014-3566 Affected product(s) and affected version(s): · IBM Image Construction and Composition Tool v2.2.1.3 · IBM Image Construction and Composition

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_sslv3_poodle_attack_vulnerability_affects_ibm_image_construction_and_composition_tool_cve_2014_3566?lang=en_us