IBM Security Bulletin: IBM TRIRIGA Application Platform Apache CXF Vulnerability (CVE-2018-8039)
Oct 24, 2018 9:01 am EDT
Categorized: High Severity
Share this post:
IBM TRIRIGA has addressed the following vulnerability. Apache CXF could allow a remote attacker to conduct a man-in-the-middle attack. The TLS hostname verification does not work correctly with com.sun.net.ssl interface. An attacker could exploit this vulnerability to launch a man-in-the-middle attack.
CVE(s): CVE-2018-8039
Affected product(s) and affected version(s):
Affected Tririga | Affected Versions |
---|---|
Tririga | 3.5 |
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10735573
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/145516
from IBM Product Security Incident Response Team https://ift.tt/2RbWoKq