Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Worklight and IBM MobileFirst Platform Foundation (CVE-2014-3570, CVE-2014-3572, CVE-2015-0204)

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes the vulnerability that has been referred to as “FREAK”. OpenSSL is used by IBM Worklight and IBM MobileFirst Platform Foundation when the optional FIPS 140-2 data-in-motion feature is enabled on the Android and iOS platforms. IBM Worklight and IBM MobileFirst Platform Foundation have addressed the applicable CVEs. CVE(s): CVE-2014-3570, CVE-2014-3572 and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_ibm_worklight_and_ibm_mobilefirst_platform_foundation_cve_2014_3570_cve_2014_3572_cve_2015_0204?lang=en_us