Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in RC4 stream cipher affects Lotus Widget Factory (CVE-2015-2808)

   
Affected software IBM
 
The RC4 “Bar Mitzvah” Attack for SSL/TLS affects the Java JREs bundled with Lotus Widget Factory. These JREs are used to run the copies of WebSphere Community Edition (WASCE) and Eclipse bundled with Lotus Widget Factory. CVE(s): CVE-2015-2808 Affected product(s) and affected version(s): Lotus Widget Factory 1.1 (Mashup Center 2.0) and Lotus Widget Factory 2.0.0.1 (Mashup Center 3.0 and 3.0.0.1). Refer to the following reference URLs for remediation and additional

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_rc4_stream_cipher_affects_lotus_widget_factory_cve_2015_2808?lang=en_us