IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM MQ AMS (CVE-2015-3194, CVE-2015-3195, CVE-2015-3196)

OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. OpenSSL is used by IBM MQ Advanced Message Security (AMS) on IBM i. IBM MQ has addressed the applicable CVEs.

CVE(s): CVE-2015-3194, CVE-2015-3195, CVE-2015-3196

Affected product(s) and affected version(s):

IBM MQ 8.0 Advanced Message Security (AMS) on IBM i only

Fix Pack 8.0.0.4 and previous maintenance levels

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/1VK7rth
X-Force Database: http://ift.tt/1KB3Vh1
X-Force Database: http://ift.tt/1QmYT4z
X-Force Database: http://ift.tt/1KB3SSD



from IBM Product Security Incident Response Team http://ift.tt/1VK7Pbf