Lucene search

K
ibmIBM82AE70B9ED2B41E62EF1FCE5137F13A8B93DB64288D0D0230D8BFDC6839DC783
HistoryJun 17, 2018 - 5:16 a.m.

Security Bulletin: OpenSSL and OpenVPN vulnerabilities affect IBM Rational Team Concert (CVE-2016-2183, CVE-2016-6329)

2018-06-1705:16:31
www.ibm.com
11

0.005 Low

EPSS

Percentile

77.2%

Summary

OpenSSL and OpenVPN vulnerabilities affect IBM Rational Team Concert. OpenSSL and OpenVPN are used by Rational BuildForge Agent shipped with IBM Rational Team Concert.

Vulnerability Details

CVEID: CVE-2016-2183**
DESCRIPTION:** OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error in the in the Triple-DES on 64-bit block cipher, used as a part of the SSL/TLS protocol. By capturing large amounts of encrypted traffic between the SSL/TLS server and the client, a remote attacker able to conduct a man-in-the-middle attack could exploit this vulnerability to recover the plaintext data and obtain sensitive information. This vulnerability is known as the SWEET32 Birthday attack.
CVSS Base Score: 3.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/116337 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-6329**
DESCRIPTION:** OpenVPN could allow a remote attacker to obtain sensitive information, caused by an error in the in the Triple-DES on 64-bit block cipher, used as a part of the SSL/TLS protocol. By capturing large amounts of encrypted traffic between the SSL/TLS server and the client, a remote attacker able to conduct a man-in-the-middle attack could exploit this vulnerability to recover the plaintext data and obtain sensitive information. This vulnerability is known as the SWEET32 Birthday attack.
CVSS Base Score: 3.7
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/116341 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

Rational Team Concert 4.0 - 4.0.7
Rational Team Concert 5.0 - 5.0.2
Rational Team Concert 6.0 - 6.0.2

Remediation/Fixes

The remediation for this Security issues is to disable triple-DES.

In the Build Forge Agent when triple-DES is enabled, it also enables SSL.

In order to disable triple-DES follow steps below:

1. Open bfagent.conf file, the file can be located at:
Windows default: C:\Program Files\IBM\Build Forge\Agent\BFAgent.conf
UNIX and Linux default: /etc/bfagent.conf

2. Add the following line in bfagent.conf after the line of “SSLProtocol”:_
SSLCipherSuite ALL:!ADH:!aNULL:!eNULL:!LOW:!EXP:!RC4:!DES-CBC3:+HIGH:+MEDIUM_

Note: if the build forge agent is not using SSL, comment out this line.

Workarounds and Mitigations

None