Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerabilities in OpenSSL including Logjam affect IBM MobileFirst Platform Foundation and IBM Worklight


Información sobre el sistema

   
Software afectado IBM

Descripción

OpenSSL vulnerabilities were disclosed by the OpenSSL Project and affect IBM MobileFirst Platform Foundation and IBM Worklight. This issue includes the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). This issue also includes the alternate chains certificate forgery vulnerability (CVE-2015-1793). IBM MobileFirst Platform Foundation and IBM Worklight have addressed the applicable CVEs. CVE(s): CVE-2015-4000, CVE-2015-1793, CVE-2015-1788,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_including_logjam_affect_ibm_mobilefirst_platform_foundation_and_ibm_worklight?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-4000 ,CVE-2015-1793 ,CVE-2015-2638 ,CVE-2015-4733 ,CVE-2015-4732 ,CVE-2015-2590 ,CVE-2015-4731 ,CVE-2015-4760 ,CVE-2015-4736 ,CVE-2015-4748 ,CVE-2015-2664 ,CVE-2015-2632 ,CVE-2015-2637 ,CVE-2015-2619 ,CVE-2015-2621 ,CVE-2015-0486 ,CVE-2015-0491 ,CVE-2015-0459 ,CVE-2015-0469 ,CVE-2015-0458 ,CVE-2015-0480 ,CVE-2015-0488 ,CVE-2015-0478 ,CVE-2015-0477 ,CVE-2015-2808 ,CVE-2015-1916 ,CVE-2015-1788 ,CVE-2015-1789 ,CVE-2015-1790 ,CVE-2015-1791 ,CVE-2015-1792 ,CVE-2015-0286 ,CVE-2015-0288 and CVE-2015-0289.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-05

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT