IBM Support

Security Bulletin: Real-time compression appliance (CVE-CVE-2015-3216)

Created by Nitzan Iron on
Published URL:
https://www.ibm.com/support/pages/node/690667
690667

Security Bulletin


Summary

Real time compression appliance affected by one Open SSL issue.

Vulnerability Details

CVEID: CVE-2015-3216

DESCRIPTION: OpenSSL is vulnerable to a denial of service, caused by an out-of-bounds memory read error in ssleay_rand_bytes() function. By sending specially crafted data, a remote attacker could exploit this vulnerability to cause the application to crash.


CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/#/vulnerabilities/103915 for the current score

CVSS Environmental Score*: Undefined


CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

Affected Products and Versions

Version

ReleaseRemediation/First Fix
4.1.24.1.2.144.1.2.14
3.9.1NANA
3.8.0NANA

Remediation/Fixes

4.1.2.14 Fix is now available - 4.1.2.14

For 3.8 IBM recommends upgrading to a fixed, supported version/release/platform of the product.

For 3.9 IBM recommends upgrading to a fixed, supported version/release/platform of the product

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off
If the CVSS vector is in the following format (AV:X/AC:X/Au:X/C:X/I:X/A:X) then CVSS scoring was scored using CVSS v2 see the following:

Complete CVSS v2 Guide

On-line Calculator v2

If the CVSS vector is in the following format (AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X) then CVSS scoring was scored using CVSS v3 see the following:

Complete CVSS v3 Guide

On-line Calculator v3

Acknowledgement

None

Change History

06 Sep 2015: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Product":{"code":"ST9SXX","label":"Network Attached Storage (NAS)->Real-time Compression Appliances STN6500, STN6800, STN7800"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
17 June 2018

UID

ssg1S1005384