Lucene search

K
ibmIBM762617D611F88A799B689B6B3E1C033FD35BF7C43760B0AEF360F438F510D1B0
HistoryJun 17, 2018 - 12:16 p.m.

Security Bulletin: Vulnerabilities in OpenSSL affect StoredIQ (CVE-2016-2107)

2018-06-1712:16:02
www.ibm.com
11

0.967 High

EPSS

Percentile

99.7%

Summary

OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by StoredIQ. StoredIQ has addressed the applicable CVEs.

Vulnerability Details

CVEID: CVE-2016-2107 DESCRIPTION: OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error when the connection uses an AES CBC cipher and the server support AES-NI. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt traffic.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/112854 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

StoredIQ v7.6

Remediation/Fixes

Product

| VRMF| APAR| Remediation/First Fix
—|—|—|—
StoredIQ| 7.6| N/A| Fix is available in 7.6.0 Fix Pack 8 on Fix Central.

Workarounds and Mitigations

None

CPENameOperatorVersion
storediqeq7.6