Lucene search

K
ibmIBM6FF75962CB7DDD7579E6FD1A7074307D64F2739B039FDA656F0F483D64BA1F23
HistoryFeb 28, 2019 - 5:15 p.m.

Security Bulletin: IBM Security Identity Adapters affected by OpenSSL RSA Key vulnerability (CVE-2018-0737)

2019-02-2817:15:01
www.ibm.com
13

EPSS

0.01

Percentile

84.1%

Summary

The Windows and z/OS Security Identity Adapters are now upgraded to a more current release to correct CVE (CVE-2018-0737) “OpenSSL RSA Key generation algorithm information disclosure”.

Vulnerability Details

CVEID: CVE-2018-0737 DESCRIPTION: OpenSSL could allow a local attacker to obtain sensitive information, caused by a cache-timing side channel attack in the RSA Key generation algorithm. An attacker with access to mount cache timing attacks during the RSA key generation process could exploit this vulnerability to recover the private key and obtain sensitive information.
CVSS Base Score: 3.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/141679&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Security Identity Manager v6.0 Adapters for Windows and z/OS platforms
Security Identity Adapters v7.x for Windows and z/OS platforms

Remediation/Fixes

Obtain the latest GA levels of 6.0 or 7.x adapters, as found on the Fix Link pages listed below: