Boletines de Vulnerabilidades

IBM Security Bulletin: Multiple vulnerabilities in AppScan Enterprise (CVE-2014-4806, CVE-2014-0411)


Información sobre el sistema

   
Software afectado IBM

Descripción

Previous releases of IBM Security AppScan Enterprise are affected by a transport layer security (TLS) timing vulnerability reported in the IBM Runtime Environment, Java(TM) Technology Edition, Version 6 and a password file temporarily created during installation. CVE(s): CVE-2014-0411 and CVE-2014-4806 Affected product(s) and affected version(s): BM Security AppScan Enterprise 9.0 IBM Security AppScan Enterprise 8.8 IBM Security AppScan Enterprise 8.7 IBM Security AppScan Enterprise 8.6

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_appscan_enterprise_cve_2014_4806_cve_2014_0411?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-0411 ,CVE-2014-4806 ,CVE-2013-5467 ,CVE-2014-0050 ,CVE-2014-3033 ,CVE-2014-4790 ,CVE-2014-3040 ,CVE-2014-3061 ,CVE-2014-3035 and CVE-2014-0907.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-28

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT