Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM® SDK for Node.js™


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on March 19, 2015 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs. CVE(s): CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292 and CVE-2015-0293 Affected product(s) and affected version(s): These vulnerabilities affect IBM SDK for Node.js v1.1.0.12 and previous releases. Refer to the following reference URLs for remediation and additional

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_ibm_sdk_for_node_js?lang=en_us

Standar resources

Property Value
CVE CVE-2015-0209 ,CVE-2015-0286 ,CVE-2015-0287 ,CVE-2015-0288 ,CVE-2015-0289 ,CVE-2015-0292 ,CVE-2015-0293 ,CVE-2015-1899 ,CVE-2015-0138 ,CVE-2014-3566 ,CVE-2014-6585 ,CVE-2014-6591 ,CVE-2014-6593 ,CVE-2015-0410 ,CVE-2015-0383 ,CVE-2014-6549 ,CVE-2014-6587 and CVE-2014-8892.

Version history

Version Comments Date
1.0 Advisory issued 2015-04-16
Ministerio de Defensa
CNI
CCN
CCN-CERT