Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in IBM SDK for Node.js affect IBM Business Process Manager Configuration Editor (CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js is used by IBM Business Process Manager Configuration Editor. IBM Business Process Manager Configuration Editor has addressed the applicable CVEs. CVE(s): CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_ibm_sdk_for_node_js_affect_ibm_business_process_manager_configuration_editor_cve_2014_3569_cve_2014_3570_cve_2014_3571_cve_2014_3572_cve_2014_8275_cve_2015

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2015-04-20
Ministerio de Defensa
CNI
CCN
CCN-CERT