Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in GSKit affect IBM WebSphere MQ (CVE-2015-0159, CVE-2015-0138 and CVE-2014-6221)

   
Affected software IBM
 
GSKit is an IBM component that is used by IBM WebSphere MQ. The GSKit that is shipped with IBM WebSphere MQ contains multiple security vulnerabilities including the "FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. CVE(s): CVE-2014-6221, CVE-2015-0138 and CVE-2015-0159 Affected product(s) and affected version(s): IBM WebSphere MQ V7.0.1 AIX, HP-UX, Linux, Solaris & Windows IBM WebSphere MQ 7.1 AIX, HP-UX, Linux, Solaris &

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_gskit_affect_ibm_websphere_mq_cve_2015_0159_cve_2015_0138_and_cve_2014_6221?lang=en_us