Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Cognos Planning (CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204)


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM Cognos Planning. IBM Cognos Planning has addressed the applicable CVEs. CVE(s): CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275 and CVE-2015-0204 Affected product(s) and affected version(s): IBM Cognos Planning 10.1 IBM Cognos Planning 10.1.1 Refer to the

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_ibm_cognos_planning_cve_2014_3570_cve_2014_3571_cve_2014_3572_cve_2014_8275_cve_2015_0204?lang=en_us

Standar resources

Property Value
CVE CVE-2014-3570 ,CVE-2014-3571 ,CVE-2014-3572 ,CVE-2014-8275 ,CVE-2015-0204 ,CVE-2013-7423 ,CVE-2014-7817 ,CVE-2014-9402 ,CVE-2015-1472 ,CVE-2014-8917 ,CVE-2014-3566 ,CVE-2014-3567 and CVE-2014-3568.

Version history

Version Comments Date
1.0 Advisory issued 2015-04-16
Ministerio de Defensa
CNI
CCN
CCN-CERT