Vulnerability Bulletins

Security Bulletin: Vulnerabilities in OpenSSL affect IBM Flex System FC5022 16Gb SAN Scalable Switch Firmware (CVE-2014-3513, CVE-2014-3567, CVE-2014-3568)

   
Affected software IBM
 
OpenSSL vulnerabilities along with SSL 3 Fallback protection (TLS_FALLBACK_SCSV) were disclosed on October 15, 2014 by the OpenSSL Project. OpenSSL is used by IBM Flex System FC5022 16Gb SAN Scalable Switch Firmware. IBM Flex System FC5022 16G SAN Scalable Switch Firmware has addressed the applicable CVEs and included the SSL 3.0 Fallback protection (TLS_FALLBACK_SCSV) provided by OpenSSL. CVE(s): CVE-2014-3513, CVE-2014-3567 and CVE-2014-3568 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_vulnerabilities_in_openssl_affect_ibm_flex_system_fc5022_16gb_san_scalable_switch_firmware_cve_2014_3513_cve_2014_3567_cve_2014_3568?lang=en_us