A fix is available for IBM SONAS, for the OpenSSL security vulnerability
CVEID:
CVE-2014-0224
DESCRIPTION:
SSL/TLS MITM vulnerability
An attacker using a carefully crafted handshake can force the use of weak keying material in OpenSSL SSL/TLS clients and servers. This can be exploited by a Man-in-the-middle (MITM) attack where the attacker can decrypt and modify traffic from the attacked client and server.
The attack can only be performed between a vulnerable client and server. OpenSSL clients are vulnerable in all versions of OpenSSL. IBM SONAS systems use OpenSSL server functionality and some versions are vulnerable (see below).
CVE-2014-0224
CVSS Base Score: 5.8
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/93586 for the current score
IBM SONAS
The product is affected when running a code releases 1.3.0.0 to 1.4.3.2
A fix for these issues is in version 1.4.3.3 of IBM SONAS. Customers running an affected version of IBM SONAS should upgrade to 1.4.3.3 or a later version, so that the fix gets applied.
Workaround(s) & Mitigation(s):
Ensure that all users who have access to the system are authenticated by another security system such as a firewall.