Vulnerability Bulletins |
IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM WebSphere MQ (HP-NSS and OVMS platforms) and Eclipse Paho MQTT C Client libraries (Windows and Linux platforms) (CVE-2014-3570, CVE-2014-35 |
|
| Affected software | IBM |
|
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by IBM WebSphere MQ on HP-NSS and HP OpenVMS platforms. CVE(s): CVE-2014-3570, CVE-2014-3572, CVE-2015-0204 and CVE-2015-0205 Affected product(s) and affected version(s): IBM MQ Appliance M2000 IBM WebSphere MQ for OpenVMS V6 IBM WebSphere MQ V5.3 for HP NonStop IBM WebSphere More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_ibm_websphere_mq_hp_nss_and_ovms_platforms_and_eclipse_paho_mqtt_c_client_libraries_windows_and_linux_platforms_cve_2014_3570_cve_2014_3572_ |
|






