Vulnerability Bulletins

IBM Security Bulletin: IBM Cognos Business Intelligence Server is affected by multiple vulnerabilities

   
Affected software IBM
 
There are multiple vulnerabilities in IBM SDK Java Technology Edition, Version 6 and IBM SDK Java Technology Edition, Version 7 that are used by IBM Cognos Business Intelligence. These issues were disclosed as part of the IBM Java SDK updates in October 2014 and January 2015. OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM Cognos

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_cognos_business_intelligence_server_is_affected_by_multiple_vulnerabilities?lang=en_us