Vulnerability Bulletins |
IBM Security Bulletin: Multiple Vulnerabilities in OpenSSL affect IBM® SDK for Node.js™ |
|
| Affected software | IBM |
|
OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs including the "DROWN: Decrypting RSA with Obsolete and Weakened eNcryption" vulnerability. CVE(s): CVE-2016-0800, CVE-2016-0705, CVE-2016-0797, CVE-2016-0702, CVE-2016-0703 and CVE-2016-0704Affected product(s) and affected version(s):These vulnerabilities affect IBM SDK for Node.js v1.1.0.19 and earlier releases. More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_openssl_affect_ibm_sdk_for_node_js?lang=en_us |
|






