IBM Security Bulletin: IBM InfoSphere Master Data Management is vulnerable to multiple OpenSSL vulnerabilities (CVE-2017-3738, CVE-2017-3737)

Oct 17, 2018 9:00 am EDT

Categorized: Medium Severity

Share this post:

IBM InfoSphere Master Data Management is vulnerable to multiple OpenSSL vulnerabilities that could cause the application to crash, an attacker to obtain information about the private key, or cause a denial of service.

CVE(s): CVE-2017-3738, CVE-2017-3737

Affected product(s) and affected version(s):

This vulnerability is known to affect the following offerings:

Affected IBM Initiate Master Data ServiceAffected Versions
IBM InfoSphere Master Data Management11.0
IBM InfoSphere Master Data Management11.3
IBM InfoSphere Master Data Management11.4
IBM InfoSphere Master Data Management11.5
IBM InfoSphere Master Data Management11.6

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10733743
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136078
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136077



from IBM Product Security Incident Response Team https://ift.tt/2OrWEYG