New POODLE update for IBM Mobile Connect
Detlev Poettgen Dezember 17 2014 08:21:15 PM
Yesterday IBM published a new Interims Fix for IBM Mobile Connect for 6.1.5.2 and for 6.1.5.1, too.Beside other Fixes there is an important update to get safe for the latest POODLE variation.
Details about the new POODLE variation can be found here:
German: http://www.heise.de/newsticker/meldung/Poodle-beisst-Load-Balancer-Lueckenhafte-Internet-Verschluesselung-mit-TLS-SSL-2482929.html
English: https://www.imperialviolet.org/2014/12/08/poodleagain.html
This is the Fixlist for 6.1.5.2:
IV66937 | Connections via a browser redirected to wrong host when connections server sends a META refresh. | 20141120 |
IV67055 | Sametime mobile authentication fails when using LTPA and alternate authentication methods such as RADIUS and Certificate authentication. | 20141120 |
IV67169 | URL rewriting is not matching DOMAIN rules. | 20141125 |
IV67689 | Certificate authentication, LTPA token expiration no always verified when loading session from the AST. Expired tokens may get sent to server and client. | 20141211 |
IV67722 | Gatway restarts regularly on Windows if Remove Users After Period Of Inactivity is enabled. | 20141211 |
IV67750 | Gatekeeper SSL connection is vulnerable to POODLE SSLv3 when SSL connections are required. | 20141211 |
IV67792 | TLS PADDING VULNERABILITY, CVE-2014-8730 | 20141211 |
IV66935 | Connections widgets do not display properly when using a browser to access a connections server. | 20141215 |
IV67873 | HTTP service redirect ports not working in 6.1.5.2 | 20141215 |
IV67878 | Sametime mobile users may fail to login when using LTPA for SSO with the Sametime proxy. | 20141215 |
Get the downloads via Fix Central: here
- Kommentare [0]