IBM Security Bulletin: IBM TRIRIGA Application Platform Apache CXF Vulnerability (CVE-2018-8039)

Oct 24, 2018 9:01 am EDT

Categorized: High Severity

Share this post:

IBM TRIRIGA has addressed the following vulnerability. Apache CXF could allow a remote attacker to conduct a man-in-the-middle attack. The TLS hostname verification does not work correctly with com.sun.net.ssl interface. An attacker could exploit this vulnerability to launch a man-in-the-middle attack.

CVE(s): CVE-2018-8039

Affected product(s) and affected version(s):

Affected TririgaAffected Versions
Tririga3.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10735573
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/145516



from IBM Product Security Incident Response Team https://ift.tt/2RbWoKq