Lucene search

K
ibmIBM6CFD1F4E92DE674FABBF5CB0AB382F8E451BC50559AF2503871032E5B3345584
HistoryJan 22, 2021 - 3:40 p.m.

Security Bulletin: Security vulnerabilities in OpenSSL affects Rational Build Forge

2021-01-2215:40:41
www.ibm.com
16

0.002 Low

EPSS

Percentile

60.1%

Summary

OpenSSL that is used by IBM Rational Build Forge has a security vulnerability. IBM Rational Build Forge has addressed the applicable CVEs.

Vulnerability Details

CVEID:CVE-2019-1551
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by an overflow in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. By performing a man-in-the-middle attack, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/172752 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Rational Build Forge 8.0 to 8.0.0.15

Remediation/Fixes

You must download the fix pack specified in the following table and apply it.

Affected Supporting Product(s) Remediation/Fix
IBM Rational Build Forge 8.0 to 8.0.0.15 Download IBM Rational Build Forge 8.0.0.16.

Workarounds and Mitigations

None.