Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in Kerberos (krb5) affect IBM Security Network Protection (CVE-2014-5352, CVE-2014-9421, CVE-2014-9422, CVE-2014-9423)

   
Affected software IBM
 
IBM Security Network Protection uses Kerberos (krb5) to provide network authentication. The Kerberos (krb5) version that is shipped with IBM Security Network Protection contains multiple security vulnerabilities that could allow a remote authenticated attacker to gain access to sensitive information. CVE(s): CVE-2014-5352, CVE-2014-9421, CVE-2014-9422 and CVE-2014-9423 Affected product(s) and affected version(s): IBM Security Network Protection 5.2 IBM Security Network Protection 5.3

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_kerberos_krb5_affect_ibm_security_network_protection_cve_2014_5352_cve_2014_9421_cve_2014_9422_cve_2014_9423?lang=en_us