IBM Support

【セキュリティ情報】 IBM Websphere Message Broker と IBM Integration Bus の DataDirect ODBC ドライバーのSSL脆弱性 ( CVE-2014-0224)

Created by Makoto Tomota on
Published URL:
https://www.ibm.com/support/pages/node/245799
245799

Security Bulletin


Summary

OpenSSL Project が提供するOpenSSLに2014年6月5日にOpenSSLのセキュリティ脆弱性が報告されました。

Vulnerability Details

WebSphere Message Broker 8.0 と IBM Integration Bus 9.0 で提供しているDataDirect ドライバーにOpenSSLのセキュリティ脆弱性が存在します。(CVE-2014-0224)

DataDirect ODBC SSL 接続をしている場合のみ影響を受けます。



CVE-ID: CVE-2014-0224
内容:OpenSSLには、SSL/TLS ハンドシェイクにおける Change Cipher Spec メッセージの処理に脆弱性が存在します。
OpenSSL を使用して保護されていたサーバ及びクライアント間の通信が中間者攻撃 (man-in-the-middle attack) により搾取・改竄される可能性があります。

CVSS Base Score: 5.8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/93586 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N)

Affected Products and Versions

IBM Websphere Message Broker V8.0

IBM Integration Bus V9.0

Remediation/Fixes

Websphere Message Broker 8.0 または IBM Integration Bus 9.0 を使用されている場合、IBM Fix Central から APAR IT02892 をダウンロードし、適用してください。

・IBM WebSphere Message Broker V8.0 : APAR IT02892 をダウンロードしてください。

・IBM Integration Bus V9.0 : APAR IT02892 をダウンロードしてください。

APAR IT02892 の修正は、

IBM WebSphere Message Broker V8.0 Fix Pack 8.0.0.6

IBM Integration Bus V9.0 Fix Pack 9.0.0.3

に含まれる予定です。

Workarounds and Mitigations

なし

Get Notified about Future Security Bulletins

References

Off
OpenSSL Project vulnerability website

【関連文書】
[IBMサイト]
この文書は、米国 IBM 社の資料を翻訳した参考文書です。翻訳元の文書は、以下のリンクよりご参照ください。
Security Bulletin : IBM Websphere Message Broker and IBM Integration Bus are affected by SSL Vulnerability in DataDirect ODBC drivers ( CVE-2014-0224)

公開済みのフィックスパックについては、以下のサイトよりご利用いただけます。
Recommended fixes for IBM Integration Bus and WebSphere Message Broker

[CVSS情報]
独立行政法人 情報処理推進機構: 共通脆弱性評価システムCVSS概説
JVN iPedia: CVSS計算ソフトウェア日本語版

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSKM8N","label":"WebSphere Message Broker"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Security","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"}],"Version":"8.0","Edition":"","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
15 June 2018

UID

swg21679967