Vulnerability Bulletins

IBM Security Bulletin: Vulnerability in SSLv3 and OpenSSL affects Power Systems Firmware (CVE-2014-3566, CVE-2014-3513, CVE-2014-3567)

   
Affected software IBM
 
OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by Power Systems Firmware. Power Systems Firmware has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL. Depending on the version, the fix also either allows SSLv3 to be disabled, or doesnt include any support for SSLv3, which is the maximum protection to eliminate any POODLE

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_sslv3_and_openssl_affects_power_systems_firmware_cve_2014_3566_cve_2014_3513_cve_2014_3567?lang=en_us