IBM Security Bulletin: API Connect OpenSSL CVE-2016-2183
OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error in the DES/3DES cipher, used as a part of the SSL/TLS protocol. This vulnerability is known as the SWEET32 Birthday attack.
CVE(s): CVE-2016-2183
Affected product(s) and affected version(s):
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2w5CQ4o
X-Force Database: http://ift.tt/2dR3VyC
The post IBM Security Bulletin: API Connect OpenSSL CVE-2016-2183 appeared first on IBM PSIRT Blog.
| Affected API Connect | Affected Versions | 
| IBM API Connect | 5.0.0.0-5.0.7.2 | 
from IBM Product Security Incident Response Team http://ift.tt/2y1Pe2z