Saturday, December 22, 2018

IBM Security Bulletin: Multiple vulnerabilities in OpenSSL affect IBM Workload Scheduler

Dec 22, 2018 9:00 am EST

Categorized: Low Severity

Share this post:

OpenSSL vulnerabilities were disclosed by the OpenSSL Project. OpenSSL is used by IBM Workload Manager. IBM Workload Manager has addressed the applicable CVEs

CVE(s): CVE-2018-0732, CVE-2018-0734

Affected product(s) and affected version(s):

IBM Workload Scheduler uses OpenSSL only for secure communication between internal processes.
For IBM Workload Scheduler Distributed, Workload Scheduler nodes are impacted by OpenSSL security exposures only if the IWS workstation has been defined with “securitylevel” set to on or enabled or force.
These security exposures do not apply to WebSphere Application Server but only to programs installed under <TWS home>/bin.
Tivoli Workload Scheduler Distributed 9.1.0 FP02 and earlier
Tivoli Workload Scheduler Distributed 9.2.0 FP03 and earlier
IBM Workload Scheduler Distributed 9.3.0 FP03 and earlier
IBM Workload Scheduler Distributed 9.4.0 FP04 and earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10792469
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/144658
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152085



from IBM Product Security Incident Response Team https://ibm.co/2EN7dAm

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.