Vulnerability Bulletins

IBM Security Bulletin: Tivoli Key Lifecycle Manager and IBM Security Key Lifecycle Manager can be affected by a vulnerability in the current IBM SDK for Java shipped by IBM WebSphere Application Serve


System information

   
Affected software IBM

Description

A security vulnerability exists in the IBM SDK for Java that is shipped with IBM WebSphere Application Server and could affect the Tivoli Key Lifecycle Manager and IBM Security Key Lifecycle Manager when using transport layer security (TLS). CVE(s): CVE-2014-0411 Affected product(s) and affected version(s): The following versions are affected: IBM Tivoli Key Lifecycle Manager (TKLM) v1.0, v2.0, v2.0.1 IBM Security Key Lifecycle Manager (ISKLM) v2.5 on distributed platforms. Refer to

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_tivoli_key_lifecycle_manager_and_ibm_security_key_lifecycle_manager_can_be_affected_by_a_vulnerability_in_the_current_ibm_sdk_for_java_shipped_by_ibm_websphere_application_se

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2014-03-21
Ministerio de Defensa
CNI
CCN
CCN-CERT