The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/80354 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV32391 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21626029 | patch vendor advisory |