Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL including Logjam affect IBM Security Access Manager for Mobile.


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on June 11, 2015 by the OpenSSL Project. This includes Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is used by IBM Security Access Manager for Mobile. IBM Security Access Manager for Mobile has addressed the applicable CVEs. CVE(s): CVE-2015-4000, CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792 andCVE-2015-3216 Affected product(s) and affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_including_logjam_affect_ibm_security_access_manager_for_mobile?lang=en_us

Standar resources

Property Value
CVE CVE-2015-4000 ,CVE-2014-8176 ,CVE-2015-1788 ,CVE-2015-1789 ,CVE-2015-1790 ,CVE-2015-1791 ,CVE-2015-1792 ,CVE-2015-3216 ,CVE-2015-2808 ,CVE-2015-1916 ,CVE-2015-0204 and CVE-2015-0138.

Version history

Version Comments Date
1.0 Advisory issued 2015-07-29
Ministerio de Defensa
CNI
CCN
CCN-CERT