Vulnerability Bulletins

IBM Security Bulletin: IBM Security Network Protection is affected by a NSS vulnerability (CVE-2014-3566)

   
Affected software IBM
 
A security vulnerability has been discovered in Network Security Services (NSS) used with IBM Security Network Protection. This update adds support for the TLS Fallback Signaling Cipher Suite Value (TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails. CVE(s): CVE-2014-3566 Affected product(s) and affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_security_network_protection_is_affected_by_a_nss_vulnerability_cve_2014_3566?lang=en_us