First published: Mon May 27 2013(Updated: )
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.3.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.3.2 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.3.3 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.4.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.4.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.5.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =6.5.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.1.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.1.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.1.2 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.2.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.2.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.2.2 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.3.0 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =7.3.1 | |
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite | =9.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2953 has a medium severity rating with a score of 4.3.
To fix CVE-2013-2953, upgrade to IBM InfoSphere Optim Data Growth for Oracle E-Business Suite version 9.1.0.3 or later.
CVE-2013-2953 affects IBM InfoSphere Optim Data Growth for Oracle E-Business Suite versions 6.x, 7.x, and 9.x prior to 9.1.0.3.
CVE-2013-2953 exposes systems to man-in-the-middle attacks due to reliance on the MD5 algorithm in X.509 certificates.
CVE-2013-2953 is associated with cryptographic issues, specifically relying on a weak hashing algorithm.