Thursday, November 30, 2017

IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Aspera Transfer Cluster Manager, faspex on Demand, Server on Demand, Application Platform on Demand, and Azure on Demand. (CVE-2016-2107, CVE-2016-2106, CVE-2016-2176)

OpenSSL vulnerabilities were disclosed on May 3, 2016 by the OpenSSL Project. OpenSSL is used by IBM Aspera Transfer Cluster Manager, IBM Aspera faspex on Demand, IBM Aspera Server on Demand, IBM Aspera Application Platform on Demand, and IBM Aspera Azure on Demand. The named on demand applications referenced above have addressed the applicable CVEs.

CVE(s): CVE-2016-2107, CVE-2016-2106, CVE-2016-2109, CVE-2016-2176

Affected product(s) and affected version(s):

IBM Aspera Transfer Clustered Manager 3.6.0 or earlier
IBM Aspera faspex on Demand 3.6.0 or earlier
IBM Aspera Server on Demand 3.6.0 or earlier
IBM Aspera Application Platform on Demand 3.6.0 or earlier
IBM Aspera Azure on Demand 3.5.6 or earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2Boj1mT
X-Force Database: http://ift.tt/1NwOQz5
X-Force Database: http://ift.tt/25myFMu
X-Force Database: http://ift.tt/1Z0wO8Z
X-Force Database: http://ift.tt/25mym4p

The post IBM Security Bulletin: Vulnerabilities in OpenSSL affect IBM Aspera Transfer Cluster Manager, faspex on Demand, Server on Demand, Application Platform on Demand, and Azure on Demand. (CVE-2016-2107, CVE-2016-2106, CVE-2016-2176) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2BnXQ4u

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.