Lucene search

K
ibmIBM96BD78A851756098C227E98FD62220AF1B5931B15BB2031029FDB3A09B830E21
HistoryMar 11, 2019 - 3:35 p.m.

Security Bulletin: A Security Vulnerability affects IBM Cloud Private Kiali Istio addon

2019-03-1115:35:01
www.ibm.com
14

0.043 Low

EPSS

Percentile

92.3%

Summary

A Security Vulnerability affects IBM Cloud Private Kiali Istio addon

Vulnerability Details

CVEID: CVE-2018-12384 DESCRIPTION: Mozilla Network Security Services (NSS), as used in Mozilla Firefox, could allow a remote attacker to obtain sensitive information, caused by the improper handling of an SSLv2-compatible ClientHello message. By conducting a passive replay attack, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 4.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/150436&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

IBM Cloud Private 3.1.1

Remediation/Fixes

IBM Cloud Private 3.1.1 patch - Available in Fix Central

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud privateeq3.1.1