IBM Security Bulletin: Vulnerability in Network Security (NSS) affects IBM SAN Volume Controller and Storwize Family (CVE-2016-1978)

A vulnerability in Network Security (NSS) affects the IBM SAN Volume Controller and Storwize Family. Though the CVE descriptions below document the vulnerabilities in the context of Mozilla Firefox, the vulnerability is resolved in the IBM SAN Volume Controller and Storwize Family products in the context of the underlying NSS service.

CVE(s): CVE-2016-1978

Affected product(s) and affected version(s):

IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500

All products are affected when running supported releases 1.1 to 7.6. Release 7.7 is not affected.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2cX7IaT
X-Force Database: http://ift.tt/1TuzxZZ



from IBM Product Security Incident Response Team http://ift.tt/2cX6BYn