IBM Security Bulletin: Multiple Vulnerabilities in OpenSSL affect IBM Worklight and IBM MobileFirst Platform Foundation

OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM Worklight and IBM MobileFirst Platform Foundation. IBM Worklight and IBM MobileFirst Platform Foundation have addressed the applicable CVEs.

CVE(s): CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106, CVE-2016-2109, CVE-2016-2176

Affected product(s) and affected version(s):

IBM Worklight Consumer Edition Versions 6.1.0.0, 6.1.0.1 and 6.1.0.2
IBM Worklight Enterprise Edition Versions 6.1.0.0, 6.1.0.1 and 6.1.0.2
IBM Mobile Foundation Consumer Edition Version 6.2.0.0 and 6.2.0.1
IBM Mobile Foundation Enterprise Edition Version 6.2.0.0 and 6.2.0.1
IBM MobileFirst Platform Foundation Version 6.3.0.0
IBM MobileFirst Platform Foundation Version 7.0.0.0
IBM MobileFirst Platform Foundation Version 7.1.0.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1Ue4OgZ
X-Force Database: http://ift.tt/1VjTr9i
X-Force Database: http://ift.tt/1NwOQz5
X-Force Database: http://ift.tt/1NwOPLs
X-Force Database: http://ift.tt/25myFMu
X-Force Database: http://ift.tt/1Z0wO8Z
X-Force Database: http://ift.tt/25mym4p



from IBM Product Security Incident Response Team http://ift.tt/1OleZB6