Lucene search

K
ibmIBM4A7A4FB6485B128D02AD0418A0B94141570EEB4F5031D456034CAF309E9A5A24
HistoryDec 19, 2018 - 4:55 a.m.

Security Bulletin: Asset Analyzer (RAA) is affected by an Apache CXF vulnerability

2018-12-1904:55:01
www.ibm.com
17

0.007 Low

EPSS

Percentile

80.9%

Summary

Rational Asset Analyzer (RAA) has addressed the following vulnerability.

Vulnerability Details

CVEID:CVE-2018-8039
DESCRIPTION: Apache CXF could allow a remote attacker to conduct a man-in-the-middle attack. The TLS hostname verification does not work correctly with com.sun.net.ssl interface. An attacker could exploit this vulnerability to launch a man-in-the-middle attack.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/145516&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)

Affected Products and Versions

| Affected Versions
โ€”|โ€”
Rational Asset Analyzer | 6.1.0.0 - 6.1.0.18

Remediation/Fixes

Product ** VRMF** ** APAR** ** Remediation / First Fix**
Rational Asset Analyzer 6.1.0.19 - Upgrade to Fix Pack 19 (6.1.0.19)

Workarounds and Mitigations

None

CPENameOperatorVersion
rational asset analyzereqany

0.007 Low

EPSS

Percentile

80.9%

Related for 4A7A4FB6485B128D02AD0418A0B94141570EEB4F5031D456034CAF309E9A5A24