Boletines de Vulnerabilidades

Security Bulletin: Security Access Manager for Enterprise Single Sign-On can be affected by a vulnerability in WebSphere Application Server (CVE-2014-0411)


Información sobre el sistema

   
Software afectado IBM

Descripción

The IBM WebSphere Application Server component provided with IBM Security Access Manager for Enterprise Single Sign-On is vulnerable to a transport layer security (TLS) timing attack. CVE(s): CVE-2014-0411 Affected product(s) and affected version(s): ISAMESSO IMS 8.1, 8.2, and 8.2.1 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21666077 X-Force Database:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_security_access_manager_for_enterprise_single_sign_on_can_be_affected_by_a_vulnerability_in_websphere_application_server_cve_2014_0411?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0411 ,CVE-2013-6440 ,CVE-2014-0881 and CVE-2014-0882.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-04

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT