Boletines de Vulnerabilidades

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and in Diffie-Hellman ciphers affects IBM InfoSphere Information Server (CVE-2015-0478 CVE-2015-0488 CVE-2015-1916 CVE-2015-4000)


Información sobre el sistema

   
Software afectado IBM

Descripción

There are multiple vulnerabilities in IBM® SDK Java™ Technology Edition, Versions 6 and 7 that are used by IBM InfoSphere Information Server. These issues were disclosed as part of the IBM Java SDK updates in April 2015. This bulletin also addresses the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is vulnerable to the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000).

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_java_sdk_and_in_diffie_hellman_ciphers_affects_ibm_infosphere_information_server_cve_2015_0478_cve_2015_0488_cve_2015_1916_cve_2015_4000?lang=

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0478 ,CVE-2015-0488 ,CVE-2015-1916 ,CVE-2015-4000 ,CVE-2015-2613 ,CVE-2015-2601 ,CVE-2015-2625 ,CVE-2015-1931 ,CVE-2015-2808 ,CVE-2015-0138 ,CVE-2015-1927 and CVE-2015-0250.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-08-14

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT