IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Storwize V7000 Unified (CVE-2015-1794, CVE-2015-3194, CVE-2015-3195, and CVE-2015-3196)

OpenSSL vulnerabilities were disclosed in December 2015 by the OpenSSL Project. OpenSSL is used by IBM Storwize V7000 Unified. IBM Storwize V7000 Unified has addressed the applicable CVEs.



CVE(s): CVE-2015-1794, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196


Affected product(s) and affected version(s):

IBM Storwize V7000 Unified

The product is affected when running a code releases 1.5.0.0 to 1.5.2.3



Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1YBY2Td
X-Force Database: http://ift.tt/1rd26hz
X-Force Database: http://ift.tt/1KB3Vh1
X-Force Database: http://ift.tt/1QmYT4z
X-Force Database: http://ift.tt/1KB3SSD


from IBM Product Security Incident Response Team http://ift.tt/1NygeMZ