Vulnerability Bulletins |
IBM Security Bulletin: SSL certificate validation disabled through a vulnerability in the Auto-Scaling for Bluemix service agent (CVE-2016-0323) |
|
| Affected software | IBM |
|
Liberty for Java applications bound to the Auto-Scaling for Bluemix service have SSL certificate validation disabled through a vulnerability in the agent for the service. The default SSL connection factory for https requests is set to bypass all trust management in this vulnerability. CVE(s): CVE-2016-0323Affected product(s) and affected version(s):This vulnerability affects all versions of Liberty for Java in IBM Bluemix prior to version v2.7-20160321-1358 that have also been bound to the More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ssl_certificate_validation_disabled_through_a_vulnerability_in_the_auto_scaling_for_bluemix_service_agent_cve_2016_03231?lang=en_us |
|






