IBM Security Bulletin: Libssh2 vulnerability affects IBM SmartCloud Entry (CVE-2016-0787 )
IBM SmartCloud Entry is vulnerable to libssh2 vulnerability. An attacker could exploit this vulnerability using the truncated Diffie-Hellman secret to launch further attacks on the system.
CVE(s): CVE-2016-0787
Affected product(s) and affected version(s):
IBM SmartCloud Entry 2.2.0 through 2.2.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.3.0 through 2.3.0.4 Appliance fix pack 6
IBM SmartCloud Entry 2.4.0 through 2.4.0.4 Appliance fix pack 6
IBM SmartCloud Entry 3.1.0 through 3.1.0.4 Appliance fix pack 21
IBM SmartCloud Entry 3.2.0 through 3.2.0.4 Appliance fix pack 21
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cg9X6P
X-Force Database: http://ift.tt/1WhPh1i
from IBM Product Security Incident Response Team http://ift.tt/2cgaYfa