Lucene search

K
ibmIBM803F869501993CC6DA1FDD05D0FD3706704DE2FFA02175BB4352BC3DC0DB20FA
HistoryMar 19, 2022 - 4:17 a.m.

Security Bulletin: A vulnerability in Java SE affects IBM Control Center (CVE-2021-35550)

2022-03-1904:17:22
www.ibm.com
24

0.002 Low

EPSS

Percentile

65.1%

Summary

A flaw in the JSSE component causes cipher suites to be offered in the wrong order, with some weaker cipher suites ahead of stronger cipher suites. The fix ensures that stronger cipher suites are offered before weaker cipher suites.

Vulnerability Details

CVEID:CVE-2021-35550
**DESCRIPTION:**An unspecified vulnerability in Java SE related to the JSSE component could allow an unauthenticated attacker to obtain sensitive information resulting in a high confidentiality impact using unknown attack vectors.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211627 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Control Center 6.1.3
IBM Control Center 6.2.1.0
IBM Control Center 6.2.0.0

Remediation/Fixes

Product

|

VRMF

|

iFix

|

Remediation

—|—|—|—

IBM Control Center

|

6.1.3.0

|

iFix12

|

Fix Central - 6.1.3.0

IBM Control Center

|

6.2.0.0

|

iFix16

|

Fix Central - 6.2.0.0 (ETA by 3-25-2022)

IBM Control Center

|

6.2.1.0

|

iFix06

|

Fix Central - 6.2.1.0 (ETA by 3-25-2022)

Workarounds and Mitigations

None