IBM Security Bulletin: API Connect OpenSSL CVE-2016-2183

OpenSSL could allow a remote attacker to obtain sensitive information, caused by an error in the DES/3DES cipher, used as a part of the SSL/TLS protocol. This vulnerability is known as the SWEET32 Birthday attack.

CVE(s): CVE-2016-2183

Affected product(s) and affected version(s):

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2w5CQ4o
X-Force Database: http://ift.tt/2dR3VyC

The post IBM Security Bulletin: API Connect OpenSSL CVE-2016-2183 appeared first on IBM PSIRT Blog.

Affected API ConnectAffected Versions
IBM API Connect5.0.0.0-5.0.7.2


from IBM Product Security Incident Response Team http://ift.tt/2y1Pe2z