Vulnerability Bulletins

IBM Security Bulletin: OpenSSL (including FREAK), RC4 stream cipher (Bar Mitzvah), and Diffie-Hellman ciphers (Logjam) vulnerabilities affect Tivoli Storage FlashCopy Manager Unix and VMware (CVE-2015

   
Affected software IBM
 
Tivoli Storage FlashCopy Manager Unix and VMware are affected by the OpenSSL vulnerabilities disclosed on January 8, 2015 by the OpenSSL Project which includes the FREAK (Factoring Attack on RSA-EXPORT keys) TLS/SSL client and server vulnerability. Tivoli Storage FlashCopy Manager Unix and VMware are also affected by the RC4 "Bar Mitzvah" Attack for SSL/TLS and the Logjam Attack on TLS connections using the Diffie-Hellman (DH) key exchanged protocol. CVE(s): CVE-2015-0204,

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_openssl_including_freak_rc4_stream_cipher_bar_mitzvah_and_diffie_hellman_ciphers_logjam_vulnerabilities_affect_tivoli_storage_flashcopy_manager_unix_and_vmware_cve_2015_0204_