IBM Security Bulletin: Multiple OpenSSL and Non-OpenSSL vulnerabilities in Node.js included in Rational Application Developer for WebSphere Software.

OpenSSL vulnerabilities were disclosed on September 22 and 26, 2016 by the OpenSSL Project. OpenSSL is used by IBM SDK for Node.js. IBM SDK for Node.js has addressed the applicable CVEs, plus three additional vulnerabilities unrelated to the OpenSSL release.

CVE(s): CVE-2016-6304, CVE-2016-6303, CVE-2016-2178, CVE-2016-6306, CVE-2016-2183, CVE-2016-7099, CVE-2016-5325

Affected product(s) and affected version(s):

IBM Rational Application Developer for WebSphere Software v9.1 and v9.5

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2eD3ZRn
X-Force Database: http://ift.tt/2dmY7tO
X-Force Database: http://ift.tt/2dmXjFz
X-Force Database: http://ift.tt/2asKHex
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2dckDn3
X-Force Database: http://ift.tt/2e5C4fq



from IBM Product Security Incident Response Team http://ift.tt/2eD2CSN