IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Sterling Connect:Direct for HP NonStop (CVE-2016-2177, CVE-2016-6306, CVE-2016-2183)

OpenSSL vulnerabilities were disclosed on September 22 and 26, 2016 by the OpenSSL Project. OpenSSL is used by IBM Sterling Connect:Direct for HP NonStop. IBM Sterling Connect:Direct for HP NonStop has addressed the applicable CVEs.

CVE(s): CVE-2016-2177, CVE-2016-6306, CVE-2016-2183

Affected product(s) and affected version(s):

IBM Sterling Connect:Direct for HP NonStop 3.6.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2fvKeKF
X-Force Database: http://ift.tt/2aPXjQq
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3VyC



from IBM Product Security Incident Response Team http://ift.tt/2fvGfOm