Vulnerability Bulletins

IBM Security Bulletin: IBM QRadar SIEM and IBM QRadar Risk Manager can be affected by Multiple Vulnerabilities in the IBM Java Runtime Environment (CVE-2015-0138, CVE-2015-0410, CVE-2015-0400, CVE-201

   
Affected software IBM
 
There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Version 6 and 7 that is used by IBM QRadar SIEM, and IBM QRadar Risk Manager. These issues were disclosed as part of the IBM Java SDK updates in January 2015. This bulletin also addresses the “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. CVE(s): CVE-2015-0138, CVE-2015-0410, CVE-2015-0400 and CVE-2014-6593 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_qradar_siem_and_ibm_qradar_risk_manager_can_be_affected_by_multiple_vulnerabilities_in_the_ibm_java_runtime_environment_cve_2015_0138_cve_2015_0410_cve_2015_0400_cve_2014