IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM® SDK for Node.js™ (CVE-2016-2107, CVE-2016-2105)

OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs.



CVE(s): CVE-2016-2107, CVE-2016-2105


Affected product(s) and affected version(s):

CVE-2016-2107 affects IBM SDK for Node.js v1.1.1.0 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v1.2.0.11 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v4.4.3.0 and earlier releases.
These vulnerabilities affect IBM SDK for Node.js v6.0.0.0.



Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1NwOSa4
X-Force Database: http://ift.tt/1NwOQz5
X-Force Database: http://ift.tt/1NwOPLs


from IBM Product Security Incident Response Team http://ift.tt/1NwON68