IBM Tivoli Endpoint Manager Server 9.1.x < 9.1.1117.0 OpenSSL Security Bypass

Medium Nessus Plugin ID 79335


The remote host is affected by a security bypass vulnerability.


According to its self-reported version, the IBM Tivoli Endpoint Manager Server installed on the remote host uses a vulnerable OpenSSL library that contains a flaw in the processing of ChangeCipherSpec messages. The flaw allows an attacker to cause usage of weak keying material leading to simplified man-in-the-middle attacks.


Upgrade to Tivoli Endpoint Manager Server 9.1.1117.0 or later.

See Also

Plugin Details

Severity: Medium

ID: 79335

File Name: ibm_tem_9_1_1117_0.nasl

Version: $Revision: 1.4 $

Type: remote

Family: Web Servers

Published: 2014/11/19

Modified: 2016/05/16

Dependencies: 66269

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:tivoli_endpoint_manager

Required KB Items: www/BigFixHTTPServer

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/06/30

Vulnerability Publication Date: 2014/06/05

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-0224

BID: 67899

OSVDB: 107729

CERT: 978508