Boletines de Vulnerabilidades

IBM Security Bulletin: Vulnerability in OpenSSL affects IBM® DB2® LUW (CVE-2015-0204)


Información sobre el sistema

   
Software afectado IBM

Descripción

OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM DB2 LUW. IBM DB2 LUW has addressed the applicable CVEs. CVE(s): CVE-2015-0204 Affected product(s) and affected version(s): IBM DB2 Advanced Copy Services included in IBM DB2 and DB2 Connect V10.1 and V10.5 editions listed below and running on AIX and Linux are affected. IBM

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_openssl_affects_ibm_db2_luw_cve_2015_0204?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-0204 ,CVE-2015-2613 ,CVE-2015-2601 ,CVE-2015-2625 ,CVE-2015-1931 ,CVE-2015-5044 ,CVE-2015-4749 ,CVE-2015-1789 ,CVE-2015-1791 and CVE-2015-1788.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-11-05

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT