IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter

OpenSSL vulnerabilities were disclosed on March 1, 2016 by the OpenSSL Project. IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter use OpenSSL and have addressed the applicable CVEs.

CVE(s): CVE-2016-0705, CVE-2016-0797

Affected product(s) and affected version(s):

ProductAffected Version
IBM Flex System FC3171 8Gb SAN Switch
IBM Flex System FC3171 8Gb SAN Pass-thru
9.1
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter7.10
QLogic Virtual Fabric Extension Module for IBM BladeCenter9.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/29A0bPu
X-Force Database: http://ift.tt/24FM7sf
X-Force Database: http://ift.tt/24FM6Eo



from IBM Product Security Incident Response Team http://ift.tt/29n0gSW