Lucene search

K
ibmIBM47DEFD4AFBF5C6135E8B5B4A41A5696678BC727C29C83EE122D25C9B5A03D112
HistoryJun 15, 2018 - 10:32 p.m.

Security Bulletin: IBM Cognos TM1 is affected by the following OpenSSL vulnerabilities: CVE-2014-0224

2018-06-1522:32:47
www.ibm.com
19

EPSS

0.974

Percentile

99.9%

Summary

Security vulnerabilities have been discovered in OpenSSL that were reported on June 5, 2014 by the OpenSSL Project

Vulnerability Details

CVE-ID: CVE-2014-0224

DESCRIPTION: OpenSSL is vulnerable to a man-in-the-middle attack, caused by the use of weak keying material in SSL/TLS clients and servers. A remote attacker could exploit this vulnerability using a specially-crafted handshake to conduct man-in-the-middle attacks to decrypt and modify traffic.

CVSS Base Score: 5.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93586&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N)

Affected Products and Versions

IBM Cognos TM1 9.5.2.3
IBM Cognos TM1 10.1.1.2
IBM Cognos TM1 10.2.0.2
IBM Cognos TM1 10.2.2

Remediation/Fixes

The recommended solution is to apply the fix in the versions listed as soon as practical:
9.5.2.3 IF5
10.1.1.2 IF1
_10.2.0.2 IF1 _
10.2.2.0 IF1

Workarounds and Mitigations

None known