Vulnerability Bulletins |
IBM Security Bulletin: Vulnerabilities in OpenSSL affect WebSphere Message Broker and IBM Integration Bus |
|
| Affected software | IBM |
|
OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes “FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL v1.0.0 is used by the DataDirect V7.x ODBC drivers shipped with WebSphere Message Broker and IBM Integration Bus. The drivers have been updated to include OpenSSL v1.0.0r to address the applicable CVEs. CVE(s): CVE-2014-3570, CVE-2014-8275, CVE-2015-0204, CVE-2015-0209, CVE-2015-0286, More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerabilities_in_openssl_affect_websphere_message_broker_and_ibm_integration_bus?lang=en_us |
|






