Skip to main content
Planview Customer Success Center

How to address RC4 Cypher Cognos Vulnerability CVE-2015-2808

Affected Products and Versions

  • IBM Cognos Controller 10.2.1
  • IBM Cognos Controller 10.2
  • IBM Cognos Controller 10.1.1
  • IBM Cognos Controller 10.1
  • IBM Cognos Controller 8.5.1
  • IBM Cognos Controller 8.5

 

Workarounds and Mitigations

The RC4 cipher suites must be disabled using Cognos Configuration by performing the following actions:

1) Start Cognos Configuration
2) Navigate to Security/Cryptography/Cognos
3) Open the supported cipher suites selection dialog
4) Select all cipher suites that have RC4 in the the name and remove them from the Current Values List. Select OK to save the new list.
5) Save and restart your service using Cognos Configuration.

You should verify applying this configuration change does not cause any compatibility issues. Not disabling the RC4 stream cipher will expose yourself to the attack described above. IBM recommends that you review your entire environment to identify other areas where you have enabled the RC4 stream cipher and take appropriate mitigation and remediation actions.

Source