Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerabilities in OpenSSL including Logjam affect IBM Security Identity Governance


Información sobre el sistema

   
Software afectado IBM

Descripción

OpenSSL vulnerabilities were disclosed on June 11, 2015 by the OpenSSL Project. This includes Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is used by IBM Security Identity Governance. IBM Security Identity Governance has addressed the applicable CVEs. CVE(s): CVE-2015-4000, CVE-2014-8176, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791 and CVE-2015-1792 Affected product(s) and affected version(s): IBM Security Identity

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_including_logjam_affect_ibm_security_identity_governance?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-4000 ,CVE-2014-8176 ,CVE-2015-1789 ,CVE-2015-1790 ,CVE-2015-1791 ,CVE-2015-1792 and CVE-2015-1835.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT