Lucene search

K
ibmIBMC756EED5745CE0D6BA8C555BB02C8B28CC96B6EAB63552877BAE325F5568690B
HistoryAug 19, 2021 - 9:49 p.m.

Security Bulletin: IBM Resilient Disaster Recovery (DR) system allows connections over TLS 1.0 (CVE-2021-29704)

2021-08-1921:49:00
www.ibm.com
6

0.001 Low

EPSS

Percentile

43.8%

Summary

IBM Resilient Disaster Recovery (DR) system allows connections over TLS 1.0

Vulnerability Details

CVEID:CVE-2021-29704
**DESCRIPTION:**IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/200660 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
Resilient OnPrem IBM Security SOAR

Remediation/Fixes

Users must upgrade to v42.0 of IBM Resilient in order to obtain a fix for this vulnerability. Connections to the DR system can no longer be made over TLS 1.0. Note that the DR system is a separately-licensed product.

You can upgrade the platform by following the instructions in the “Upgrading DR” section in the IBM Knowledge Center.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

43.8%

Related for C756EED5745CE0D6BA8C555BB02C8B28CC96B6EAB63552877BAE325F5568690B