Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Endpoint Manager Platform 9.1 is affected by two OpenSSL vulnerabilities, the "POODLE" vulnerability, and two XSS vulnerabilities


Información sobre el sistema

   
Software afectado IBM

Descripción

Vulnerabilities have been discovered in the OpenSSL libraries used by IBM Endpoint Manager 9.1. Two of these vulnerabilities could allow attackers to create a denial of services attack or to craft a man-in-middle attack to hijack sessions or to get sensitive information. Attackers could also hijack a browser session to gain sensitive session information using the "POODLE" attack. Attackers could also get sensitive information from the Relay Diagnostics page or Web Reports through

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_endpoint_manager_platform_9_1_is_affected_by_two_openssl_vulnerabilities_the_poodle_vulnerability_and_two_xss_vulnerabilities?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-4812 ,CVE-2014-6123 ,CVE-2014-6135 ,CVE-2014-6119 ,CVE-2014-6122 ,CVE-2014-6121 ,CVE-2013-2566 ,CVE-2014-3567 ,CVE-2014-0224 and CVE-2014-3566.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-12-27

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT