First published: Thu Dec 07 2017(Updated: )
IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | =9.0 | |
IBM InfoSphere Guardium z/OS | =9.1 | |
IBM InfoSphere Guardium z/OS | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1271 is classified as a moderate severity vulnerability.
To fix CVE-2017-1271, update to a newer version of IBM Security Guardium that addresses this vulnerability.
CVE-2017-1271 affects IBM Security Guardium versions 9.0, 9.1, and 9.5.
CVE-2017-1271 is a vulnerability related to inadequate selection of security algorithms.
The risks associated with CVE-2017-1271 include potential exposure to weaker cryptographic protections during communication.