Vulnerability Bulletins |
IBM Security Bulletin: Four (4) Vulnerabilities in OpenSSL affect IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems ( CVE-2014-3513, CVE-2014-3566, CVE-2014-3567, and CVE-2014-3568) |
|
| Affected software | IBM |
|
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL), Transport Layer Security (TLS), and Datagram Transport Layer Security (DTLS) protocols which is used by IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems. OpenSSL had a vulnerability which allowed forceful downgrade of the communication to SSL 3.0, which is vulnerable to the padding oracle Attack, when using block cipher suites in cipher block chaining (CBC) mode. This attack on SSL 3.0’s CBC mode is also More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_four_4_vulnerabilities_in_openssl_affect_ibm_flashsystem_and_tms_ramsan_710_720_810_and_820_systems_cve_2014_3513_cve_2014_3566_cve_2014_3567_and_cve_2014_3568?lang=en_us |
|






