IBM Security Bulletin: IBM Security Access Manager appliances are affected by vulnerabilities in OpenSSL

Numerous vulnerabilities have been identified in OpenSSL. The IBM Security Access Manager appliances use OpenSSL and are affected by these vulnerabilities.

CVE(s): CVE-2016-6304, CVE-2016-6306, CVE-2016-2183, CVE-2016-2177, CVE-2016-2178, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-6302

Affected product(s) and affected version(s):

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2k9NTld
X-Force Database: http://ift.tt/2dmY7tO
X-Force Database: http://ift.tt/2dmYpRr
X-Force Database: http://ift.tt/2dR3VyC
X-Force Database: http://ift.tt/2aPXjQq
X-Force Database: http://ift.tt/2asKHex
X-Force Database: http://ift.tt/2dR5fBu
X-Force Database: http://ift.tt/2dmWOvf
X-Force Database: http://ift.tt/2dmXLUk
X-Force Database: http://ift.tt/2dR45pA
X-Force Database: http://ift.tt/2dR4fNY



from IBM Product Security Incident Response Team http://ift.tt/2k9FqOS