Lucene search

K
ibmIBM84BB486A16164E9E9FFD8E6D5DA45CDDD2999475349031D618B321E598A27C51
HistoryJul 24, 2020 - 10:49 p.m.

Security Bulletin: OpenSSL Vulnerability Affects IBM Sterling Connect:Express for UNIX (CVE-2018-0737)

2020-07-2422:49:37
www.ibm.com
12

0.01 Low

EPSS

Percentile

83.9%

Summary

A security vulnerability has been disclosed on 16th April 2018 by the OpenSSL Project. OpenSSl is used by IBM Sterling Connect:Express for UNIX. IBM Sterling Connect:Express for UNIX has addressed the applicable CVE.

Vulnerability Details

CVEID: CVE-2018-0737 DESCRIPTION: OpenSSL could allow a local attacker to obtain sensitive information, caused by a cache-timing side channel attack in the RSA Key generation algorithm. An attacker with access to mount cache timing attacks during the RSA key generation process could exploit this vulnerability to recover the private key and obtain sensitive information.
CVSS Base Score: 3.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/141679&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Sterling Connect:Express for UNIX 1.5.0.15

All versions prior to and including 1.5.0.15 iFix 150-1509

Remediation/Fixes

Apply the OpenSSL 1.0.2p updater for Connect:Express for Unix available on Fix Central.

Workarounds and Mitigations

None.