Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in MD5 Signature and Hash Algorithm affects IBM DataPower Gateways (CVE-2015-7575)

   
Affected software IBM
 
The MD5 “SLOTH” vulnerability on TLS 1.2 affects IBM DataPower Gateways. CVE(s): CVE-2015-7575Affected product(s) and affected version(s):IBM DataPower Gateway appliances all versions through 6.0.0.17, 6.0.1.13, 7.0.0.10, 7.1.0.7. Versions 7.2.0.0 and later are not affected by this vulnerability. Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21974965X-Force Database:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_md5_signature_and_hash_algorithm_affects_ibm_datapower_gateways_cve_2015_7575?lang=en_us