Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL including Logjam affect Rational Application Developer for WebSphere Software (CVE-2015-4000, CVE-2015-1793)


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed by the OpenSSL Project and affect Rational Application Developer for WebSphere Software. This includes the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). This also includes the alternate chains certificate forgery vulnerability (CVE-2015-1793). Rational Application Developer for WebSphere Software has addressed the applicable CVEs. CVE(s): CVE-2015-4000 and CVE-2015-1793 Affected product(s) and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_including_logjam_affect_rational_application_developer_for_websphere_software_cve_2015_4000_cve_2015_1793?lang=en_us

Standar resources

Property Value
CVE CVE-2015-4000 ,CVE-2015-1793 ,CVE-2015-1920 ,CVE-2015-0491 ,CVE-2015-0459 ,CVE-2015-0469 ,CVE-2015-0478 ,CVE-2015-1916 ,CVE-2015-0488 and CVE-2015-5380.

Version history

Version Comments Date
1.0 Advisory issued 2015-07-18
Ministerio de Defensa
CNI
CCN
CCN-CERT