IBM Security Bulletin: A vulnerability in OpenSSL affects IBM DataPower Gateways (CVE-2016-2183)

A vulnerability in the SSL/TLS protocol affects the ISAM Access Manager client and JMS. IBM DataPower Gateways has fully addressed the applicable CVE in version 7.5.2, and in earlier releases it was addressed with a combination of a code fix and a workaround.

CVE(s): CVE-2016-2183

Affected product(s) and affected version(s):

IBM DataPower Gateway, versions 7.0.0.0-7.0.0.17, 7.1.0.0-7.1.0.14, 7.2.0.0-7.2.0.11, 7.5.0.0-7.5.0.5, 7.5.1.0-7.5.1.4, 7.5.2.0-7.5.2.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2oUGA4n
X-Force Database: http://ift.tt/2dR3VyC

The post IBM Security Bulletin: A vulnerability in OpenSSL affects IBM DataPower Gateways (CVE-2016-2183) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2oUPEXl