Vulnerability Bulletins

IBM Security Bulletin: IEM for Security Configuration Management 9.0 product: SCA 1.5 and SUA 2.x product versions are vulnerable to SSLv3 "POODLE issue" (CVE-2014-3566)

   
Affected software IBM
 
TLS protocol support used in Software Usage Analysis (SUA) and Security Configuration Analytics (SCA) is vulnerable to POODLE TLS attack (CVE-2014-3566). This attack enables a man-in-the-middle attacker to decrypt and intercept communications, including user-server and agent-server messages. CVE(s): CVE-2014-3566 Affected product(s) and affected version(s): Software Usage Analysis (SUA) all versions of 2.x Security Configuration Analysis (SCA) 1.5 component of IBM Endpoint Manager for

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_iem_for_security_configuration_management_9_0_product_sca_1_5_and_sua_2_x_product_versions_are_vulnerable_to_sslv3_poodle_issue_cve_2014_3566?lang=en_us