Lucene search

K
ibmIBM3BA67C7A0DDBE49028B4B8FAE6636AD247D3074A6215C005837CCB772370E9FA
HistoryJun 17, 2018 - 10:31 p.m.

Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Worklight (CVE-2014-3509, CVE-2014-5139)

2018-06-1722:31:20
www.ibm.com
13

0.05 Low

EPSS

Percentile

92.8%

Summary

There are multiple vulnerabilities in OpenSSL that is used by the optional FIPS 140-2 data-in-motion feature in IBM Worklight. These issues were disclosed on August 6, 2014 by the OpenSSL Project.

Vulnerability Details

CVE-ID: CVE-2014-3509**
DESCRIPTION**: OpenSSL is vulnerable to a denial of service, caused by a race condition in the ssl_parse_serverhello_tlsext() code. If a multithreaded client connects to a malicious server using a resumed session, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/95159&gt; for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVE-ID: CVE-2014-5139**
DESCRIPTION**: OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference when an SRP ciphersuite is specified without being properly negotiated with the client. A remote attacker could exploit this vulnerability to cause the client to crash.
CVSS Base Score: 5
CVSS Temporal Score: See _<https://exchange.xforce.ibmcloud.com/vulnerabilities/95166&gt;_ for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

  • IBM Worklight Consumer Edition Versions 6.1.0.0, 6.1.0.1 and 6.1.0.2

  • IBM Worklight Enterprise Edition Versions 6.1.0.0, 6.1.0.1 and 6.1.0.2

  • IBM Worklight Foundation Consumer Edition Version 6.2.0.0 and 6.2.0.1

  • IBM Worklight Foundation Enterprise Edition Version 6.2.0.0 and 6.2.0.1

Remediation/Fixes

Download the latest interim fix for your product and version:

V6.1.x: IBM Worklight Consumer Edition, IBM Worklight Enterprise Edition

V6.2.x: IBM Worklight Foundation Consumer Edition, IBM Worklight Foundation Enterprise Edition

Workarounds and Mitigations

None