IBM Support

webMethods Knowlegebase : Testing Failure : OpenSSL `ChangeCipherSpec' 'Man-In-The-Middle' Vulnerability (1759954)

Troubleshooting


Problem

It seems that the SSL service was susceptible to a vulnerability that could result in sensitive data being decrypted. In all instances, the remote service accepted an SSL `ChangeCipherSpec' message at an incorrect point in the handshake, leading to weak keys being used, and then attempted to decrypt an SSL record using those weak keys.

Using OpenSSL, updated to the latest available version, will solve the above problem?

Document Location

Worldwide

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSQG2X","label":"IBM webMethods Managed File Transfer"},"ARM Category":[{"code":"a8mKe00000000AQIAY","label":"webMethods ActiveTransfer Server (MAT)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Windows Server 2008"}],"Version":"9.6"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
20 March 2025

UID

ibm17202896