Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Cognos TM1 including a vulnerabiltiy in the RC4 stream ciphers (CVE-2015-2808, CVE-2014-3569).

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. OpenSSL is used by IBM Cognos TM1. IBM Cognos TM1 has addressed the applicable CVE. The RC4 “Bar Mitzvah” Attack for SSL/TLS affects IBM Cognos TM1 CVE(s): CVE-2015-2808 and CVE-2014-3569 Affected product(s) and affected version(s): IBM Cognos TM1 10.2.2 IBM Cognos TM1 10.2..0.2 IBM Cognos TM1 10.1.1 IBM Cognos TM1 9.5.2 Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_ibm_cognos_tm1_including_a_vulnerabiltiy_in_the_rc4_stream_ciphers_cve_2015_2808_cve_2014_35691?lang=en_us