Vulnerability Bulletins

Security Bulletin: Vulnerabilities in SSLv3 and OpenSSL affect System x Integrated Management Module (IMM1) (CVE-2014-3566, CVE-2014-3568)

   
Affected software IBM
 
SSLv3 contains a vulnerability that has been referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. This bulletin addresses the POODLE issue which affected the IMM1 as well as another issue in OpenSSL disclosed in October 2014. CVE(s): CVE-2014-3566 and CVE-2014-3568 Affected product(s) and affected version(s): The following IMM code levels exhibit this issue: All versions 1.00 to 1.46 The following platforms are be affected: System x3500 M2, Type 7839, any

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_vulnerabilities_in_sslv3_and_openssl_affect_system_x_integrated_management_module_imm1_cve_2014_3566_cve_2014_3568?lang=en_us