IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter

OpenSSL vulnerabilities were disclosed on December 3, 2015 by the OpenSSL Project. IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru Firmware, QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module and QLogic Virtual Fabric Extension Module for IBM BladeCenter use OpenSSL and have addressed the applicable CVEs.

CVE(s): CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, CVE-2015-1794

Affected product(s) and affected version(s):

ProductAffected Version
IBM Flex System FC3171 8Gb SAN Switch
IBM Flex System FC3171 8Gb SAN Pass-thru
9.1
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for
BladeCenter
7.10
QLogic Virtual Fabric Extension Module for IBM BladeCenter9.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/29n0cSW
X-Force Database: http://ift.tt/1SOfzoa
X-Force Database: http://ift.tt/1Ra8QHG
X-Force Database: http://ift.tt/1SOfxwJ
X-Force Database: http://ift.tt/1Ra8QHI
X-Force Database: http://ift.tt/1Ra8Pn5



from IBM Product Security Incident Response Team http://ift.tt/29n0ARx