Vulnerability Bulletins

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM MQ AMS (CVE-2015-3194, CVE-2015-3195, CVE-2015-3196)

   
Affected software IBM
 
OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. OpenSSL is used by IBM MQ Advanced Message Security (AMS) on IBM i. IBM MQ has addressed the applicable CVEs.CVE(s): CVE-2015-3194, CVE-2015-3195, CVE-2015-3196Affected product(s) and affected version(s):IBM MQ 8.0 Advanced Message Security (AMS) on IBM i only Fix Pack 8.0.0.4 and previous maintenance levelsRefer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin:

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-vulnerabilities-in-openssl-affect-ibm-mq-ams-cve-2015-3194-cve-2015-3195-cve-2015-3196/