Lucene search

K
ibmIBMD9698EB2CF81825958A16C40C281E4200E50280EC0B7C07E689F7539BB227DB6
HistoryJun 23, 2018 - 3:45 a.m.

Security Bulletin: Vulnerability in the OpenSSL Library Affects IBM Tealeaf Customer Experience (CVE-2017-3735)

2018-06-2303:45:19
www.ibm.com
8

0.028 Low

EPSS

Percentile

90.7%

Summary

A Vulnerability in the OpenSSL library used by the IBM Tealeaf Customer Experience could permit a a remote attacker to obtain sensitive information.

Vulnerability Details

CVEID: CVE-2017-3735**
DESCRIPTION:** OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error while parsing an IPAdressFamily extension in an X.509 certificate. An attacker could exploit this vulnerability to trigger an out-of-bounds read, resulting in an incorrect text display of the certificate.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/131047&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM Tealeaf Customer Experience v9.0.2, v9.0.1, v8.8.x and v8.7.x

Remediation/Fixes

Product

|

VRMF

|

Remediation/First Fix

—|—|—

IBM Tealeaf Customer Experience

|

9.0.2A

| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Enterprise%20Marketing%20Management&product=ibm/Other+software/Tealeaf+Customer+Experience&release=All&platform=All&function=fixId&fixids=9.0.2.5359_9.0.2A_IBM_Tealeaf_CXUpgrade_FixPack7&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=fc

IBM Tealeaf Customer Experience

|

9.0.2

| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Enterprise%20Marketing%20Management&product=ibm/Other+software/Tealeaf+Customer+Experience&release=All&platform=All&function=fixId&fixids=9.0.2.1403_IBM_Tealeaf_CXUpgrade_FixPack7&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=fc

Customers using versions 9.0.1, 8.8.x and 8.7.x should upgrade to v9.0.2 and apply the fix.

Workarounds and Mitigations

None