IBM Security Bulletin: Vulnerabilities in OpenSSL affect Sterling Connect:Express for UNIX (CVE-2016-7055, CVE-2017-3731 and CVE-2017-3732)

OpenSSL vulnerabilities were disclosed on January 26, 2017 by the OpenSSL Project. OpenSSL is used by IBM Sterling Connect:Express for UNIX. IBM Sterling Connect:Express for UNIX has addressed the applicable CVEs.

CVE(s): CVE-2016-7055, CVE-2017-3731, CVE-2017-3732

Affected product(s) and affected version(s):

IBM Sterling Connect:Express for UNIX 1.5.0.14
– All versions prior to 1.5.0.14

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2mizepN
X-Force Database: http://ift.tt/2hjUUfe
X-Force Database: http://ift.tt/2knsB3D
X-Force Database: http://ift.tt/2kDymIW

The post IBM Security Bulletin: Vulnerabilities in OpenSSL affect Sterling Connect:Express for UNIX (CVE-2016-7055, CVE-2017-3731 and CVE-2017-3732) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2miwAQQ