IBM Security Bulletin: IBM Java Quarterly CPU - Jan 2014 affecting Rational Application Developer (CVE-2014-0411)

Timing differences based on validity of TLS messages can be exploited to decrypt the entire session. CVE(s): CVE-2014-0411 Affected product(s) and affected version(s): Rational Application Developer 9.0.1 and earlier ...



via IBM Product Security Incident Response Team http://ibm.co/1iJ7W5m