Boletines de Vulnerabilidades

IBM Security Bulletin: Multiple vulnerabilities impact DS8000 HMC


Información sobre el sistema

   
Software afectado IBM

Descripción

There are multiple vulnerabilities in the DS8000 HMC which are covered in this bulletin. These include: * The Padding Oracle On Downgraded Legacy Encryption (POODLE) SSLv3 vulnerability (CVE-2014-3566). * Multiple vulnerabilities in OpenSSL that were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by DS8000 HMC. * Multiple vulnerabilities in IBM Runtime Environment Java Technology Edition that is used by DS8000 HMC. These issues were disclosed as part of the IBM Java SDK

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_impact_ds8000_hmc?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-3566 ,CVE-2014-3513 ,CVE-2014-3567 ,CVE-2014-3568 ,CVE-2015-0138 ,CVE-2014-3569 ,CVE-2014-3570 ,CVE-2014-3572 ,CVE-2014-8275 ,CVE-2015-0205 ,CVE-2014-6593 ,CVE-2014-8892 ,CVE-2015-0410 ,CVE-2014-9293 ,CVE-2014-9294 ,CVE-2014-9297 and CVE-2014-9298.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-04-09

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT