The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg1IO15761 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74303 | vdb entry |
http://www.securitytracker.com/id?1026939 | vdb entry |
http://www.ibm.com/support/docview.wss?uid=swg1IO16036 | vendor advisory |
http://www.securityfocus.com/bid/53043 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21591272 | |
http://www.ibm.com/support/docview.wss?uid=swg1IO16035 | vendor advisory |