Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Security Network Protection

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM Security Network Protection. IBM Security Network Protection has addressed the applicable CVEs including the “DROWN: Decrypting RSA with Obsolete and Weakened eNcryption" vulnerability. CVE(s): CVE-2016-0800, CVE-2016-0702, CVE-2016-0705, CVE-2016-0797 and CVE-2015-3197Affected product(s) and affected version(s):IBM Security Network Protection 5.3.1 IBM Security Network Protection

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_openssl_affect_ibm_security_network_protection2?lang=en_us