Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect Tivoli Workload Scheduler (CVE-2016-0705, CVE-2016-0702, CVE-2016-0800, CVE-2016-0701)

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. OpenSSL is used by Tivoli Workload Scheduler. Tivoli Workload Scheduler has addressed the applicable CVEs including the “DROWN: Decrypting RSA with Obsolete and Weakened eNcryption" vulnerability. CVE(s): CVE-2016-0800, CVE-2016-0705, CVE-2016-0702 and CVE-2016-0701Affected product(s) and affected version(s):TWS uses OpenSSL only for secure communication between internal processes. For Tivoli Workload

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_openssl_affect_tivoli_workload_scheduler_cve_2016_0705_cve_2016_0702_cve_2016_0800_cve_2016_0701?lang=en_us