Medium Severity

Security Bulletin: Vulnerabilities in OpenSSL affect AIX (CVE-2019-1547, CVE-2019-1563)

Share this post:

There are vulnerabilities in OpenSSL used by AIX.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
AIX 7.1
AIX 7.2
VIOS 2.2
VIOS 3.1


The following fileset levels are vulnerable:
key_fileset = osrcaix
Fileset Lower Level Upper Level Key
openssl.base key_w_fs
openssl.base key_w_fs
        A. 0.9.8, 1.0.1 OpenSSL versions are out-of-support. Customers are advised to upgrade to currently supported OpenSSL 1.0.2 version.
        B. Latest level of OpenSSL fileset is available from the web download site:
To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in the AIX user's guide.
Example:  lslpp -L | grep -i openssl.base

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin:

More stories

Security Bulletin: SQL injection vulnerability in IBM Business Automation Workflow and IBM Business Process Manager (BPM) (CVE-2019-4479)

Feb 26, 2020 7:00 pm EST | Medium Severity

IBM Business Process Manager and IBM Business Automation Workflow is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. more

Security Bulletin: Bypass security restrictions in WAS Liberty

Feb 26, 2020 7:00 pm EST | Medium Severity

IBM MobileFirst Platform Foundation has addressed the following vulnerability. Bypass security restrictions in WAS Liberty . more

Security Bulletin: SQL Injection Vulnerability Affects IBM Sterling B2B Integrator EBICS (CVE-2019-4597)

Feb 25, 2020 7:00 pm EST | Medium Severity

IBM Sterling B2B Integrator has addressed the SQL injection vulnerability. more