IBM Support

Security Bulletin: Vulnerability in SSLv3 affects InfoSphere BigInsights
(CVE-2014-3566)

Created by Suresh Thalamati on
Published URL:
https://www.ibm.com/support/pages/node/254351
254351

Security Bulletin


Summary

SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. SSLv3 is enabled in BigInsights.

Vulnerability Details

CVE-ID: CVE-2014-3566

DESCRIPTION: InfoSphere BigInsights could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via a POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and access the plain text of encrypted connections.

CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/97013 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

Affected Products and Versions

IBM InfoSphere BigInsights: 2.0-3.0.0.1

Remediation/Fixes

For version 3.0, and 3.0.0.1: Upgrade to the fix pack version InfoSphere BigInsights 3.0.0.2.

Workarounds and Mitigations

For all affected versions of InfoSphere BigInsights, IBM recommends disabling SSLv3. The server SSL configuration should be modified to use SSL protocol TLS as shown below to disable SSLv3.

The following steps should be performed to disable SSLv3 and enable TLS:

  1. Login as a BigInsights admin user.
  2. Stop the console: $BIGINSIGHTS_HOME/bin/stop.sh console
  3. Update the console configuration file:
    1. Find ssl configuration element in $BIGINSIGHTS_HOME/console/wlp/usr/servers/waslp-server/server.xml.
    2. Add attribute sslProtocol="TLS".
      For example: <ssl clientAuthenticationSupported="true" id="defaultSSLSettings" keyStoreRef="defaultKeyStore" sslProtocol="TLS"/>
  4. Restart the console: $BIGINSIGHTS_HOME/bin/start.sh console

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

None

Change History

21 Oct 2014: Original Version Published
29 Jan 2015: Added fix information for BigInsights 3.0, and 3.0.0.1.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSCRJT","label":"IBM Db2 Big SQL"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.0.0;2.1.0;2.1.1;2.1.2;3.0","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
08 April 2021

UID

swg21687661