IBM Security Bulletin: Sweet32 Birthday attacks on 64-bit block ciphers in TLS affect Content Manager for z/OS (CVE-2016-2183)

System SSL’s SSL V2, SSL V3 and TLS protocols support the use of Triple DES ciphers and are susceptible to the Sweet32 Birthday attack vulnerability. This vulnerability affects exploiters acting as either clients or servers. Content Manager 8 Resource Manager on z/OS uses System SSL and addressed the applicable CVE.

CVE(s): CVE-2016-2183

Affected product(s) and affected version(s):

Content Manager for z/OS 8.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2gAKt66
X-Force Database: http://ift.tt/2dR3VyC



from IBM Product Security Incident Response Team http://ift.tt/2hF1dyb