Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK affect IBM SPSS Collaboration and Deployment Services (CVE-2015-0478, CVE-2015-0488, CVE-2015-2808, CVE-2015-4000)


System information

   
Affected software IBM

Description

There are multiple vulnerabilities in IBM SDK Java Technology Edition, Versions 1.6 and 1.7 that are used by IBM SPSS Collaboration and Deployment Services. These issues were disclosed as part of the IBM Java SDK updates in April 2015 and IBM Java SDK update addressing TLS protocol vulnerability involving DHE_EXPORT ciphersuite commonly referred as “logjam attack.” CVE(s): CVE-2015-0478, CVE-2015-0488, CVE-2015-2808 and CVE-2015-4000 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_java_sdk_affect_ibm_spss_collaboration_and_deployment_services_cve_2015_0478_cve_2015_0488_cve_2015_2808_cve_2015_4000?lang=en_us

Standar resources

Property Value
CVE CVE-2015-0478 ,CVE-2015-0488 ,CVE-2015-2808 ,CVE-2015-4000 ,CVE-2015-1916 ,CVE-2015-0204 ,CVE-2015-1905 ,CVE-2015-1906 ,CVE-2015-0410 and CVE-2014-6593.

Version history

Version Comments Date
1.0 Advisory issued 2015-07-21
Ministerio de Defensa
CNI
CCN
CCN-CERT