CVE-2014-0848

IBM Netezza Performance Portal < 2.0.0.4 - Weak SSL Cipher Suite Configuration

Title source: llm
STIX 2.1

Description

The (1) ssl.conf and (2) httpd.conf files in the Apache HTTP Server component in IBM Netezza Performance Portal 2.0 before 2.0.0.4 have weak SSLCipherSuite values, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90723
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21665278

Scores

EPSS 0.0085
EPSS Percentile 54.5%

Details

CWE
CWE-310
Status published
Products (4)
ibm/netezza_performance_portal 2.0.0.0
ibm/netezza_performance_portal 2.0.0.1
ibm/netezza_performance_portal 2.0.0.2
ibm/netezza_performance_portal 2.0.0.3
Published Mar 26, 2014
Tracked Since Feb 18, 2026