Lucene search

K
ibmIBMF14E46DECF8CA0C3C9CF8B2CDAEE5FAB0ECF7815EBF5C422B06AF0DD10EAE2F3
HistoryJun 17, 2018 - 3:12 p.m.

Security Bulletin: IBM MessageSight is affected by the following OpenSSL vulnerabilities: (CVE-2014-0224, and CVE-2014-0195)

2018-06-1715:12:13
www.ibm.com
14

0.974 High

EPSS

Percentile

99.9%

Summary

Security vulnerabilities have been discovered in OpenSSL that were reported on June 5, 2014 by the OpenSSL Project.

Vulnerability Details

C****VE-ID:CVE-2014-0224

**DESCRIPTION:**OpenSSL is vulnerable to a man-in-the-middle attack, caused by the use of weak keying material in SSL/TLS clients and servers. A remote attacker could exploit this vulnerability using a specially-crafted handshake to conduct man-in-the-middle attacks to decrypt and modify traffic.

CVSS Base Score: 5.8
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93586&gt;[](&lt;https://exchange.xforce.ibmcloud.com/vulnerabilities/93586&gt;) for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N)

CVE-ID:CVE-2014-0195

**DESCRIPTION:**OpenSSL is vulnerable to a buffer overflow. By sending invalid DTLS packet fragments, a remote attacker could exploit this vulnerability to overrun the client or server and execute arbitrary code on a DTLS client or server.

CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/93588&gt; for the current score
CVSS Environmental Score*: UndefinedCVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Affected Products and Versions

This vulnerability is known to affect the following offerings:

  • IBM MessageSight Server v1.0
  • IBM MessageSight Server v1.1

The vulnerability does NOT affect any version or release of the following:

  • IBM MessageSight JMS Client
  • IBM MessageSight Resource Adaptor

IBM Java JSSE does not use OpenSSL.

Remediation/Fixes

The IBM MessageSight Server firmware has been updated to use a newer version of OpenSSL, which contains a fix for the reported OpenSSL vulnerabilities.

Product VRMF Remediation/First Fix
IBM MessageSight 1.x.x.x 1.1.0.1
A firmware update can be downloaded from: IBM Support: Fix Central

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm messagesighteq1.0
ibm messagesighteq1.1