Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Flex System Chassis Management Module (CMM) is affected by multiple vulnerabilities in OpenSSL including Logjam


Información sobre el sistema

   
Software afectado IBM

Descripción

OpenSSL vulnerabilities were disclosed on June 11, 2015 by the OpenSSL Project. This includes Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchange protocol (CVE-2015-4000). OpenSSL is used by IBM Flex Chassis Management Module (CMM). Flex Chassis Management Module has addressed the vulnerabilities. CVE(s): CVE-2015-4000, CVE-2014-8176, CVE-2015-1789, CVE-2015-1790, CVE-2015-1792, CVE-2015-1791, CVE-2015-3216 and CVE-2015-1788 Affected product(s) and affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_flex_system_chassis_management_module_cmm_is_affected_by_multiple_vulnerabilities_in_openssl_including_logjam?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2015-4000 ,CVE-2014-8176 ,CVE-2015-1789 ,CVE-2015-1790 ,CVE-2015-1792 ,CVE-2015-4993 ,CVE-2015-4998 ,CVE-2015-5001 ,CVE-2015-7413 ,CVE-2015-4872 ,CVE-2015-1791 ,CVE-2015-3216 and CVE-2015-1788.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-12-05

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT