The Netty library is vulnerable affecting the Rational Integration Tester component in IBM Rational Test Workbench.
CVE ID: CVE-2014-3488
Description: Netty is vulnerable to a denial of service, caused by an error in SslHandler. A remote attacker could exploit this vulnerability using a specially-crafted SSLv2Hello message to exhaust all available CPU resources and cause the application to enter into an infinite loop.
CVSS Base Score: 5.0 **CVSS Temporal Score:**See <https://exchange.xforce.ibmcloud.com/vulnerabilities/95285> for the current score *CVSS Environmental Score:**Undefined CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Rational Integration Tester component in Rational Test Workbench versions:
The fixes for the CVE(s) mentioned above have been incorporated into the 3.9.5 release of the Netty library, and included in a set of new fixpacks available from IBM.
Upgrade your installation as follows:
Visit IBM Fix Central to search for, download and apply the following fixpacks for your version of product:
None