Lucene search

K
ibmIBM92765D81072035449BBC85AE8BA3B1253ED518E7D82BB9301CFF2908A95278FA
HistoryJun 15, 2018 - 10:44 p.m.

Security Bulletin: OpenSSL vulnerability in IBM Algo Audit and Compliance (CVE-2015-3197)

2018-06-1522:44:41
www.ibm.com
17

0.018 Low

EPSS

Percentile

88.2%

Summary

OpenSSL could allow a remote attacker to conduct man-in-the-middle attacks. OpenSSL is used by IBM Algo Audit and Compliance.

Vulnerability Details

CVEID: CVE-2015-3197**
DESCRIPTION:** OpenSSL could allow a remote attacker to conduct man-in-the-middle attacks, caused by an error related to the negotiation of disabled SSLv2 ciphers by malicious SSL/TLS clients. An attacker could exploit this vulnerability to conduct man-in-the-middle attacks.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110235 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)

Affected Products and Versions

IBM Algo Audit and Compliance versions 2.1.0

Remediation/Fixes

Download and install IBM Algo Audit and Compliance version 2.1.0.3 Interim Fix 2 from Fix Central, details available at <http://www-01.ibm.com/support/docview.wss?uid=swg24042349&gt;

CPENameOperatorVersion
algo audit and complianceeq2.1