Lucene search

K
ibmIBM8A87036F5C290A7EB193FCCEE8F258BACCA1FC57CC5D8A56759A27F177621DF5
HistoryJun 17, 2018 - 3:13 p.m.

Security Bulletin: Vulnerabilities in OpenSSL affect IBM MessageSight (CVE-2015-1788)

2018-06-1715:13:11
www.ibm.com
12

0.567 Medium

EPSS

Percentile

97.7%

Summary

Denial of service in GSKit may affect IBM MessageSight, if using MQ Connectivity support

Vulnerability Details

CVEID:CVE-2015-1788

OpenSSL is vulnerable to a denial of service, caused by an error when processing an ECParameters structure over a specially crafted binary polynomial field. A remote attacker could exploit this vulnerability to cause the application to enter into an infinite loop.

CVSS Base Score: 5

CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/103778 for the current score

CVSS Environmental Score*: Undefined

CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

IBM MessageSight 1.2

Remediation/Fixes

Product

|
VRMF|
APAR|
Remediation/First Fix
—|—|—|—

IBM MessageSight

|

1.2

|

IT12294

|

1.2.0.3-IBM-IMA-IFIT12295

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm messagesighteq1.2