Lucene search

K
ibmIBM969B869C858F640A6283D702296C23A13A8A64586452AB7E6A37D5DA25ABC7B6
HistoryJun 12, 2020 - 8:34 p.m.

Security Bulletin: IBM Spectrum Protect Plus vulnerable to Logjam (CVE-2015-4000)

2020-06-1220:34:38
www.ibm.com
29

EPSS

0.974

Percentile

99.9%

Summary

A port used by VADP is reported to be vulnerable to Logjam (CVE-2015-4000).

Vulnerability Details

CVEID:CVE-2015-4000
**DESCRIPTION:**The TLS protocol could allow a remote attacker to obtain sensitive information, caused by the failure to properly convey a DHE_EXPORT ciphersuite choice. An attacker could exploit this vulnerability using man-in-the-middle techniques to force a downgrade to 512-bit export-grade cipher. Successful exploitation could allow an attacker to recover the session key as well as modify the contents of the traffic. This vulnerability is commonly referred to as “Logjam”.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/103294 for the current score.
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus 10.1.0-10.1.5

Remediation/Fixes

Spectrum Protect Plus Release First Fixing VRM Level **APAR **** ** Platform Link to Fix
10.1 10.1.6 IT32099 Linux <https://www.ibm.com/support/pages/node/5693313&gt;

Workarounds and Mitigations

None