Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in OpenSSL affects IBM® DB2® (CVE-2015-1788)


Información sobre el sistema

   
Software afectado IBM

Descripción

An OpenSSL denial of service vulnerability disclosed by the OpenSSL Project affects GSKit. IBM DB2 uses GSKit and addressed the applicable CVE. CVE(s): CVE-2015-1788 Affected product(s) and affected version(s): Customers who have Secure Sockets Layer (SSL) support enabled in their DB2 database system or DB2 client are affected. SSL support is not enabled in DB2 by default. All fix pack levels of IBM DB2 V9.7, V10.1 and V10.5 editions listed below and running on AIX, Linux, HP, Solaris

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_openssl_affects_ibm_db2_cve_2015_1788?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-1788 ,CVE-2015-4929 ,CVE-2015-0488 ,CVE-2015-0478 ,CVE-2015-2808 ,CVE-2015-1916 ,CVE-2015-0204 ,CVE-2015-2613 ,CVE-2015-2601 ,CVE-2015-1931 ,CVE-2015-1789 ,CVE-2015-1791 and CVE-2015-4000.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-10-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT