Boletines de Vulnerabilidades

IBM Security Bulletin: Tivoli Key Lifecycle Manager and IBM Security Key Lifecycle Manager can be affected by a vulnerability in the current IBM SDK for Java shipped by IBM WebSphere Application Serve


Información sobre el sistema

   
Software afectado IBM

Descripción

A security vulnerability exists in the IBM SDK for Java that is shipped with IBM WebSphere Application Server and could affect the Tivoli Key Lifecycle Manager and IBM Security Key Lifecycle Manager when using transport layer security (TLS). CVE(s): CVE-2014-0411 Affected product(s) and affected version(s): The following versions are affected: IBM Tivoli Key Lifecycle Manager (TKLM) v1.0, v2.0, v2.0.1 IBM Security Key Lifecycle Manager (ISKLM) v2.5 on distributed platforms. Refer to

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_tivoli_key_lifecycle_manager_and_ibm_security_key_lifecycle_manager_can_be_affected_by_a_vulnerability_in_the_current_ibm_sdk_for_java_shipped_by_ibm_websphere_application_se

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-03-21

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT