Imported from previous forum
[ original email was from Ryan Pierce - rpierce@taltrade.com ]
The following is an advisory from RSA:
http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL-J_3.x.SecurityBulletin.html
It indicates a vulnerability in an SSL server running BSAFE SSL-J 3.x where client authentication can be bypassed.
Given that FIX sessions over SSL likely would use client authentication, it is possible that this may affect FIX servers based on the vulnerable RSA BSAFE code.