Boletines de Vulnerabilidades

IBM Security Bulletin: IBM Security Directory Server can be affected by a vulnerability in IBM WebSphere Application Server (CVE-2014-0411)


Información sobre el sistema

   
Software afectado IBM

Descripción

The IBM WebSphere Application Server component provided with IBM Security Directory Server is vulnerable to a transport layer security (TLS) timing attack. CVE(s): CVE-2014-0411, CVE-2014-041 and CVE-2012-3325 Affected product(s) and affected version(s): ISDS 6.1, 6.2, 6.3, and 6.3.1 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www.ibm.com/support/docview.wss?uid=swg21667352 X-Force Database:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_security_directory_server_can_be_affected_by_a_vulnerability_in_ibm_websphere_application_server_cve_2014_0411?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0411 ,CVE-2012-3325 ,CVE-2013-4353 ,CVE-2013-6450 ,CVE-2013-6449 ,CVE-2013-4057 ,CVE-2013-4058 ,CVE-2013-4059 ,CVE-2013-4066 and CVE-2013-4067.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-19

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT