Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect WebSphere Transformation Extender, including RC4 stream cipher vulnerability (CVE-2014-6593, CVE-2015-0383, CVE-2015-0410, CV

   
Affected software IBM
 
There are multiple vulnerabilities in IBM® Runtime Environment Java™ Technology Edition used by WebSphere Transformation Extender. These issues were disclosed as part of the IBM Java SDK updates in January 2015. In addition, the RC4 “Bar Mitzvah” Attack for SSL/TLS affects WebSphere Transformation Extender. CVE(s): CVE-2014-6593, CVE-2015-0383, CVE-2015-0410 and CVE-2015-2808 Affected product(s) and affected version(s): Affected products: WebSphere

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_java_runtime_affect_websphere_transformation_extender_including_rc4_stream_cipher_vulnerability_cve_2014_6593_cve_2015_0383_cve_2015_0410_cve_