CVE-2015-0138

Description

GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the FREAK issue, a different vulnerability than CVE-2015-0204.

Risk Information

Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.057

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.11Windows
Multiple vulnerabilities are fixed in IBM HTTP 6.1.0.47Windows
Vulnerabilities CVE-2014-8730,CVE-2011-3192,CVE-2015-1829,CVE-2015-0138 are fixed in IBM HTTP 6.0.2.43Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.39Windows
Vulnerabilities CVE-2015-3183,CVE-2015-2808,CVE-2015-0138 are fixed in IBM HTTP 8.5.5.6Windows
Multiple vulnerabilities are fixed in IBM WebSphere 6.1.0.47Windows
Vulnerabilities CVE-2015-0138 are fixed in IBM WebSphere 6.0.2.43Windows
Multiple vulnerabilities are fixed in IBM WebSphere 7.0.0.39Windows
Vulnerabilities CVE-2015-0138 are fixed in IBM WebSphere 8.5.5.6Windows
Vulnerabilities CVE-2015-0138 are fixed in IBM WebSphere 8.0.0.11Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 8.5.1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234