Vulnerability Bulletins

IBM Security Bulletin: IBM i is affected by the following OpenSSL vulnerabilities: CVE-2014-3513, CVE-2014-3567 and CVE-2014-3568.

   
Affected software IBM
 
OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by IBM i. IBM i has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL. CVE(s): CVE-2014-3513, CVE-2014-3567 and CVE-2014-3568 Affected product(s) and affected version(s): Releases V5R3, V5R4, 6.1, 7.1 and 7.2 of IBM i are affected. Refer to the following reference URLs

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_i_is_affected_by_the_following_openssl_vulnerabilities_cve_2014_3513_cve_2014_3567_and_cve_2014_3568?lang=en_us