IBM Security Bulletin: Vulnerabilities in OpenSSL and PHP affect IBM Tealeaf Customer Experience (CVE-2016-2107, CVE-2016-6290, CVE-2016-7125)
OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM Tealeaf Customer Experience. IBM Tealeaf Customer Experience has addressed the applicable CVEs. The IBM Tealeaf Customer Experience Passive Capture Application (PCA) component uses a version of PHP with reported security issues.
CVE(s): CVE-2016-2107, CVE-2016-6290, CVE-2016-7125
Affected product(s) and affected version(s):
IBM Tealeaf Customer Experience v8.0-v9.0.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2hAVtFm
X-Force Database: http://ift.tt/1NwOQz5
X-Force Database: http://ift.tt/2hAMkgm
X-Force Database: http://ift.tt/2fudZ0v
from IBM Product Security Incident Response Team http://ift.tt/2hAOMDq