Release date:
Updated on:
Affected Systems:
RSA Security rsa bsafe SSL-J 6.x
RSA Security rsa bsafe SSL-J 5.x
Unaffected system:
RSA Security rsa bsafe SSL-J 6.1.x
RSA Security rsa bsafe SSL-J 6.0.2
RSA Security rsa bsafe SSL-J 5.1.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65597
CVE (CAN) ID: CVE-2014-0626
Rsa bsafe security software products provide developers with a complete set of solutions to help them achieve various security goals of their applications.
Rsa bsafe SSL-J 5.1.3, 6.0.2, 6.1.1 during TLS handshakes, clients or servers receive unencrypted unauthenticated application data, which attackers can exploit to obtain sensitive information.
<* Source: vendor
Link: http://www.securityfocus.com/archive/1/531099
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RSA Security
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://knowledge.rsasecurity.com