Medium Severity

Security Bulletin: Vulnerabilities in OpenSSL affect AIX (CVE-2019-1547, CVE-2019-1563)

Share this post:

There are vulnerabilities in OpenSSL used by AIX.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
AIX 7.1
AIX 7.2
VIOS 2.2
VIOS 3.1

 

The following fileset levels are vulnerable:
        
key_fileset = osrcaix
 
Fileset Lower Level Upper Level Key
openssl.base 1.0.2.500 1.0.2.1801 key_w_fs
openssl.base 20.13.102.1000 20.16.102.1801 key_w_fs
 
Note:
        A. 0.9.8, 1.0.1 OpenSSL versions are out-of-support. Customers are advised to upgrade to currently supported OpenSSL 1.0.2 version.
 
        B. Latest level of OpenSSL fileset is available from the web download site:
  
To find out whether the affected filesets are installed on your systems, refer to the lslpp command found in the AIX user's guide.
 
Example:  lslpp -L | grep -i openssl.base

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1116033

More stories

Security Bulletin: SQL injection vulnerability in IBM Business Automation Workflow and IBM Business Process Manager (BPM) (CVE-2019-4479)

Feb 26, 2020 7:00 pm EST | Medium Severity

IBM Business Process Manager and IBM Business Automation Workflow is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. ...read more


Security Bulletin: Bypass security restrictions in WAS Liberty

Feb 26, 2020 7:00 pm EST | Medium Severity

IBM MobileFirst Platform Foundation has addressed the following vulnerability. Bypass security restrictions in WAS Liberty . ...read more


Security Bulletin: SQL Injection Vulnerability Affects IBM Sterling B2B Integrator EBICS (CVE-2019-4597)

Feb 25, 2020 7:00 pm EST | Medium Severity

IBM Sterling B2B Integrator has addressed the SQL injection vulnerability. ...read more