IBM Security Bulletin: IBM InfoSphere Master Data Management is vulnerable to multiple OpenSSL vulnerabilities (CVE-2017-3738, CVE-2017-3737)
Oct 17, 2018 9:00 am EDT
Categorized: Medium Severity
Share this post:
IBM InfoSphere Master Data Management is vulnerable to multiple OpenSSL vulnerabilities that could cause the application to crash, an attacker to obtain information about the private key, or cause a denial of service.
CVE(s): CVE-2017-3738, CVE-2017-3737
Affected product(s) and affected version(s):
This vulnerability is known to affect the following offerings:
Affected IBM Initiate Master Data Service | Affected Versions |
IBM InfoSphere Master Data Management | 11.0 |
IBM InfoSphere Master Data Management | 11.3 |
IBM InfoSphere Master Data Management | 11.4 |
IBM InfoSphere Master Data Management | 11.5 |
IBM InfoSphere Master Data Management | 11.6 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10733743
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136078
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136077
from IBM Product Security Incident Response Team https://ift.tt/2OrWEYG