Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in Sametime Unified Telephony (OpenSSL: CVE-2014-3508 to CVE-2014-3512, CVE-2014-5139. Apache Tomcat: CVE-2014-0099, CVE-2014-0119, CVE-2013-4444)

   
Affected software IBM
 
Sametime Unified Telephony (SUT) uses OpenSSL and Apache Tomcat and needs to be updated to fix several security vulnerability issues found in OpenSSL and in Apache Tomcat. CVE(s): CVE-2014-3508, CVE-2014-3509, CVE-2014-3510, CVE-2014-3511, CVE-2014-3512, CVE-2014-5139, CVE-2014-0099, CVE-2014-0119 and CVE-2013-4444 Affected product(s) and affected version(s): Sametime Unified Telephony 8.5.2 and 9. Refer to the following reference URLs for remediation and additional vulnerability

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_sametime_unified_telephony_openssl_cve_2014_3508_to_cve_2014_3512_cve_2014_5139_apache_tomcat_cve_2014_0099_cve_2014_0119_cve_2013_4444?lang=en_us