Vulnerability Bulletins

Security Bulletin: Vulnerabilities in OpenSSL affect Integrated Management Module II (IMM2) (CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204, CVE-2015-0205, CV


System information

   
Affected software IBM

Description

OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes "FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerability. OpenSSL is used by Integrated Management Module II (IMM2). IMM2 has addressed the applicable CVEs. CVE(s): CVE-2015-0204, CVE-2014-3569, CVE-2014-3570, CVE-2014-3571, CVE-2014-3572, CVE-2014-8275, CVE-2015-0205 andCVE-2015-0206 Affected product(s) and affected version(s): All IMM2 firmware releases

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_vulnerabilities_in_openssl_affect_integrated_management_module_ii_imm2_cve_2014_3569_cve_2014_3570_cve_2014_3571_cve_2014_3572_cve_2014_8275_cve_2015_0204_cve_2015_0205_cve_2015_

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2015-05-30
Ministerio de Defensa
CNI
CCN
CCN-CERT