IBM Security Bulletin: Vulnerability in OpenSSL affects ProtecTIER (CVE-2016-2108)
OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by ProtecTIER. ProtecTIER has addressed the applicable CVEs.
CVE(s): CVE-2016-2108
Affected product(s) and affected version(s):
These products are affected by this vulnerability:
· ProtecTIER Enterprise Edition (PID 5639-PTA) – TS7650G
· ProtecTIER Appliance Edition (PID 5639-PTB) – TS7650AP1
· ProtecTIER Entry Edition (PID 5639-PTC) – TS7610 / TS7620
· ProtecTIER Gateway for System Z (PID 5639-FPA)
The code versions impacted are 1.2.x, 2.4.x, 2.5.x, 3.1.x, 3.2.x, 3.3.x and 3.4.x
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/29A09aj
X-Force Database: http://ift.tt/1VjTr9i
from IBM Product Security Incident Response Team http://ift.tt/29n0HMN