Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability with Diffie-Hellman ciphers may affect IBM WebSphere Application Server (CVE-2015-4000)


Información sobre el sistema

   
Software afectado IBM

Descripción

The LogJam Attack on Diffie-Hellman ciphers (CVE-2015-4000) may affect some configurations of IBM WebSphere Application Server Full Profile, IBM WebSphere Application Server Liberty Profile, and IBM WebSphere Application Server Hypervisor Edition. The IBM HTTP Server used by WebSphere Application Server is not affected. CVE(s): CVE-2015-4000 Affected product(s) and affected version(s): The following IBM WebSphere Application Server Versions may be affected: Version 8.5 and 8.5.5

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_with_diffie_hellman_ciphers_may_affect_ibm_websphere_application_server_cve_2015_4000?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-4000 ,CVE-2015-1967 ,CVE-2015-0488 ,CVE-2015-0478 ,CVE-2015-2808 ,CVE-2015-1916 and CVE-2015-0204.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-06-26

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT