IBM Support

Security Bulletin: SSLv3 POODLE Attack (CVE-2014-3566)

Created by Shyamala Rajagopalan on
Published URL:
https://www.ibm.com/support/pages/node/523361
523361

Security Bulletin


Summary

SSLv3 POODLE Attack (CVE-2014-3566) impacts IBM Service Deliver Manager.

Vulnerability Details

Review the following security bulletins for vulnerability details and information about fixes:

Affected Products and Versions

Principal Product and Version(s)

Affected Supporting Product and Version
IBM Service Delivery Manager 7.xWebSphere Application Server 6.1.0.0 through 6.1.0.47

IBM HTTP Server (All versions)

IBM Tivoli Monitoring
  • Tivoli Enterprise Management Servers (TEMS) - 6.20 through 6.30 FP4 (all releases)
  • Agents – IBM Tivoli Monitoring Shared Libraries (ax component on UNIX/Linux) or Tivoli Enterprise Monitoring Agent Framework (GL component on Windows) - 6.20 through 6.30 FP4
  • Tivoli Enterprise Portal Server (TEPS)
    • embedded WebSphere Application Server – 6.20 through 6.30 FP4
    • IBM HTTP Server (IHS) - 6.23 through 6.30 FP1
  • Portal server communication with portal clients
    • HTTP – 6.23 through 6.30 FP1
    • IIOP - Not affected
    • SSL/IIOP – 6.20 through 6.30 FP4
  • Situation Update Forwarder (SUF) – 6.20 through 6.30 FP3

SmartCloud Cost Management 2.1, 2.1.0.1, 2.1.0.2

Tivoli Usage and Accounting Manager 7.3 (including all related fix packs)

IBM Tivoli Directory Server 6.0, 6.1, 6.2, 6.3

IBM Security Directory Server 6.3.1

OpenSSL 0.9.8

Get Notified about Future Security Bulletins

References

Off

Change History

* 18 January 2016: Updated links to bulletins
* 06 January 2015: Original copy published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"SSBH2C","label":"IBM Service Delivery Manager"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Security","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"7.2.1;7.2.2;7.2.3;7.2.4","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}},{"Product":{"code":"SSFG5E","label":"Tivoli Service Automation Manager"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"Security","Platform":[{"code":"PF033","label":"Windows"},{"code":"PF002","label":"AIX"},{"code":"PF016","label":"Linux"}],"Version":"7.2.1;7.2.2;7.2.3;7.2.4","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
17 June 2018

UID

swg21693977