Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect PowerKVM (Multiple CVEs)


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on March 19, 2015 by the OpenSSL Project. OpenSSL is used by PowerKVM. PowerKVM has addressed the applicable CVEs CVE(s): CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288, CVE-2015-0289, CVE-2015-0292 and CVE-2015-0293 Affected product(s) and affected version(s): PowerKVM 2.1 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_powerkvm_multiple_cves?lang=en_us

Standar resources

Property Value
CVE CVE-2015-0209 ,CVE-2015-0286 ,CVE-2015-0287 ,CVE-2015-0288 ,CVE-2015-0289 ,CVE-2015-0292 ,CVE-2015-0293 ,CVE-2015-0135 ,CVE-2013-7423 ,CVE-2014-7817 ,CVE-2014-9402 ,CVE-2015-1472 ,CVE-2015-0138 ,CVE-2014-6549 ,CVE-2014-6585 ,CVE-2014-6587 ,CVE-2014-6591 ,CVE-2014-6593 and CVE-2014-8892.

Version history

Version Comments Date
1.0 Advisory issued 2015-04-17
Ministerio de Defensa
CNI
CCN
CCN-CERT