IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Tivoli Netcool/Reporter

OpenSSL vulnerabilities were disclosed on December 3, 2015, January 28, 2016, and March 1, 2016 by the OpenSSL Project. OpenSSL is used by IBM Tivoli Netcool/Reporter. IBM Tivoli Netcool/Reporter has addressed the applicable CVEs including the “DROWN: Decrypting RSA with Obsolete and Weakened eNcryption” vulnerability.

CVE(s): CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-3197, CVE-2016-0800, CVE-2016-0705, CVE-2016-0798, CVE-2016-0797, CVE-2016-0799, CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-2842

Affected product(s) and affected version(s):

2.2.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/28KX6dj
X-Force Database: http://ift.tt/1KB3Vh1
X-Force Database: http://ift.tt/1QmYT4z
X-Force Database: http://ift.tt/1KB3SSD
X-Force Database: http://ift.tt/1rd26hw
X-Force Database: http://ift.tt/1WhPjGA
X-Force Database: http://ift.tt/1Tg5wqO
X-Force Database: http://ift.tt/1N2N4p3
X-Force Database: http://ift.tt/1Tg5wqQ
X-Force Database: http://ift.tt/1N2N4p5
X-Force Database: http://ift.tt/1Tg5v6h
X-Force Database: http://ift.tt/1N2N4p7
X-Force Database: http://ift.tt/1Tg5wH8
X-Force Database: http://ift.tt/24fOBfM



from IBM Product Security Incident Response Team http://ift.tt/28KX8lw