Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in SSL/TLS affects IBM Control Center and IBM Sterling Connect:Direct Browser (CVE-2015-2808)

   
Affected software IBM
 
SSL/TLS contains a vulnerability referred to as the RC4 Bar Mitzvah Attack. RC4 ciphers are enabled in Control Center and Connect:Direct Browser. CVE(s): CVE-2015-2808 Affected product(s) and affected version(s): IBM Control Center 6.0.0 through 6.0.0.0 iFix01 IBM Sterling Control Center 5.4.2 through 5.4.2.1 iFix01 IBM Sterling Control Center 5.4.1 through 5.4.1.0 iFix02 IBM Sterling Control Center 5.4.0 through 5.4.0.1 iFix03 IBM Sterling Control Center 5.3 through 5.3.0.4 iFix02 IBM

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_ssl_tls_affects_ibm_control_center_and_ibm_sterling_connect_direct_browser_cve_2015_2808?lang=en_us