Security Bulletin
Summary
SSLv3 POODLE Attack (CVE-2014-3566) impacts IBM Service Deliver Manager.
Vulnerability Details
Review the following security bulletins for vulnerability details and information about fixes:
- Security Bulletin: Vulnerability in SSLv3 affects IBM WebSphere Application Server (CVE-2014-3566)
- Security Bulletin: Vulnerability in SSLv3 affects IBM HTTP Server (CVE-2014-3566)
- Security Bulletin: Vulnerability in SSLv3 affects IBM Tivoli Monitoring (CVE-2014-3566)
Note: Only apply the patch on the IBM Tivoli Monitoring server and endpoints. Do not make the workaround changes for endpoints as mentioned in this ITM bulletin.
- Security Bulletin: Vulnerability in SSLv3 affects SmartCloud Cost Management / Tivoli Usage and Accounting Manager (CVE-2014-3566)
- Security Bulletin: Vulnerability in SSLv3 affects Directory Server (CVE-2014-3566)
Note: If using AIX or Red Hat Enterprise Linux, upgrade from OpenSSL 0.9.8 to OpenSSL 0.9.8zd.
Affected Products and Versions
|
Principal Product and Version(s) | Affected Supporting Product and Version |
| IBM Service Delivery Manager 7.x | WebSphere Application Server 6.1.0.0 through 6.1.0.47 IBM HTTP Server (All versions) IBM Tivoli Monitoring
SmartCloud Cost Management 2.1, 2.1.0.1, 2.1.0.2 Tivoli Usage and Accounting Manager 7.3 (including all related fix packs) IBM Tivoli Directory Server 6.0, 6.1, 6.2, 6.3 IBM Security Directory Server 6.3.1 OpenSSL 0.9.8 |
Get Notified about Future Security Bulletins
References
Change History
* 18 January 2016: Updated links to bulletins
* 06 January 2015: Original copy published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
swg21693977