Boletines de Vulnerabilidades

IBM Security Bulletin: Multiple vulnerabilities in Java™ affect the IBM® FlashSystem™ V840 (CVEs 2015-0204, 2015-0488, and 2015-1916)


Información sobre el sistema

   
Software afectado IBM

Descripción

There are multiple vulnerabilities in IBM SDK Java Technology Edition version that is used by the IBM FlashSystem V840. These issues were disclosed as part of the IBM SDK, Java Technology Edition Quarterly CPU - April 2015. A man-in-the-middle exploit of one of these vulnerabilities could result in brute-force decryption of TLS/SSL traffic between vulnerable clients and servers. Exploit of the other vulnerabilities could result in a denial of service. CVE(s): CVE-2015-0488, CVE-2015-1916

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_java_affect_the_ibm_flashsystem_v840_cves_2015_0204_2015_0488_and_2015_1916?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0488 ,CVE-2015-0478 ,CVE-2015-1916 ,CVE-2015-2808 ,CVE-2014-0227 ,CVE-2015-0209 ,CVE-2015-0286 ,CVE-2015-0289 and CVE-2015-0204.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT