Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM MessageSight (CVE-2016-0800, CVE-2016-0705 and CVE-2016-0797)

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM MessageSight. IBM MessageSight has addressed the applicable CVEs including the “DROWN: Decrypting RSA with Obsolete and Weakened eNcryption" vulnerability. CVE(s): CVE-2016-0800, CVE-2016-0705 and CVE-2016-0797Affected product(s) and affected version(s):IBM MessageSight 1.1 and 1.2 Refer to the following reference URLs for remediation and additional vulnerability details:Source

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_openssl_affect_ibm_messagesight_cve_2016_0800_cve_2016_0705_and_cve_2016_0797?lang=en_us