Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect Tivoli Storage Productivity Center October 2014 CPU


System information

   
Affected software IBM

Description

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition that is shipped with IBM Tivoli Storage Productivity Center. This also includes a fix for the Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). These issues were disclosed as part of the IBM Java SDK updates in October 2014. CVE(s): CVE-2014-6513, CVE-2014-6457, CVE-2014-6468, CVE-2014-6502, CVE-2014-6504, CVE-2014-6506, CVE-2014-6511,CVE-2014-6512, CVE-2014-6519,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_java_sdk_affect_tivoli_storage_productivity_center_october_2014_cpu?lang=en_us

Standar resources

Property Value
CVE CVE-2014-3566 ,CVE-2014-0130 ,CVE-2014-7829 ,CVE-2015-0209 ,CVE-2015-0286 ,CVE-2015-0287 ,CVE-2015-0288 ,CVE-2015-0289 ,CVE-2015-0292 ,CVE-2015-0293 ,CVE-2014-6513 ,CVE-2014-6457 ,CVE-2014-6468 ,CVE-2014-6502 ,CVE-2014-6504 ,CVE-2014-6506 ,CVE-2014-6511 ,CVE-2014-6512 ,CVE-2014-6519 ,CVE-2014-6456 ,CVE-2014-6503 ,CVE-2014-6532 ,CVE-2014-4288 ,CVE-2014-6493 ,CVE-2014-6492 ,CVE-2014-6458 ,CVE-2014-6466 ,CVE-2014-6476 ,CVE-2014-6515 ,CVE-2014-6531 ,CVE-2014-6527 ,CVE-2014-6558 and CVE-2014-3065.

Version history

Version Comments Date
1.0 Advisory issued 2015-04-19
Ministerio de Defensa
CNI
CCN
CCN-CERT