Lucene search

K
ibmIBMFD48BA74DC3A1C3984E282E9336A9AAC5D63A6863D7227C72593B2FEC3CC6C79
HistoryJun 15, 2018 - 7:09 a.m.

Security Bulletin: IBM API Connect is affected by an OPENSSL vulnerability (CVE-2017-3735)

2018-06-1507:09:13
www.ibm.com
14

EPSS

0.028

Percentile

90.6%

Summary

IBM API Connect Developer Portal has addressed the following vulnerability.

OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error while parsing an IPAdressFamily extension in an X.509 certificate. An attacker could exploit this vulnerability to trigger an out-of-bounds read, resulting in an incorrect text display of the certificate.

Vulnerability Details

CVEID:CVE-2017-3735**
DESCRIPTION: *OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error while parsing an IPAdressFamily extension in an X.509 certificate. An attacker could exploit this vulnerability to trigger an out-of-bounds read, resulting in an incorrect text display of the certificate.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/131047 for the current score
CVSS Environmental Score
: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

Affected API Connect

|

Affected Versions

—|—
IBM API Connect| 5.0.8.0-5.0.8.1

Remediation/Fixes

Affected Product

|

Addressed in VRMF

|

APAR

|

Remediation / First Fix

—|—|—|—
IBM API Connect

5.0.8.0-5.0.8.1| 5.0.8.2| LI80128| Addressed in IBM API Connect V5.0.8.2.

Follow this link and find the “APIConnect-Portal” package:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7EWebSphere&product=ibm/WebSphere/IBM+API+Connect&release=5.0.8.1&platform=All&function=all

Workarounds and Mitigations

None