Vulnerability Bulletins

IBM Security Bulletin: Storage HMC OpenSSL upgrade to address cryptographic vulnerabilities.


System information

   
Affected software IBM

Description

Storage HMC included in releases prior to v7.2 use OpenSSL versions that had errors in cryptographic libraries that could allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption). CVE(s): CVE-2012-2131, CVE-2012-2110, CVE-2012-0884, CVE-2012-0050, CVE-2011-4108, CVE-2011-4576, CVE-2011-4577, CVE-2011-4619, CVE-2012-0027, CVE-2011-3207, CVE-2011-3210, CVE-2011-0014, CVE-2010-4252, CVE-2010-3864, CVE-2010-0742 and CVE-2010-1633 Affected

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_storage_hmc_openssl_upgrade_to_address_cryptographic_vulnerabilities?lang=en_us

Standar resources

Property Value
CVE CVE-2012-2131 ,CVE-2012-2110 ,CVE-2012-0884 ,CVE-2012-0050 ,CVE-2011-4108 ,CVE-2011-4576 ,CVE-2011-4577 ,CVE-2011-4619 ,CVE-2012-0027 ,CVE-2011-3207 ,CVE-2011-3210 ,CVE-2011-0014 ,CVE-2010-4252 ,CVE-2010-3864 ,CVE-2010-0742 ,CVE-2014-0879 ,CVE-2014-0895 ,CVE-2014-0904 ,CVE-2013-6724 and CVE-2010-1633.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-15
Ministerio de Defensa
CNI
CCN
CCN-CERT