Infinite loop in OpenSSL - CVE-2022-0778
Published: March 15, 2022 / Updated: October 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the BN_mod_sqrt() function when processing an ASN.1 certificate that contains elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. A remote attacker can supply a specially crafted certificate to the TLS server or client, consume all available system resources and cause denial of service conditions.
Affected software
HPE ProLiant DL160 Gen8 Server
HPE ProLiant DL380 Gen9 Server
HPE ProLiant DL380p Gen8 Server
HPE ProLiant DL380e Gen8 Server
HPE ProLiant DL360 Gen9 Server
HPE ProLiant DL360p Gen8 Server
HPE ProLiant DL360e Gen8 Server
HPE ProLiant DL320e Gen8 v2 Server
HPE ProLiant DL320e Gen8 Server
HPE ProLiant DL180 Gen9 Server
HPE ProLiant DL160 Gen9 Server
HPE ProLiant DL385p Gen8 (AMD)
HPE ProLiant DL120 Gen9 Server
HPE ProLiant DL80 Gen9 Server
HPE ProLiant DL60 Gen9 Server
HPE ProLiant DL20 Gen9 Server
HPE ProLiant ML350 Gen9 Server
HPE ProLiant ML350p Gen8 Server
HPE ProLiant ML350e Gen8 v2 Server
HPE ProLiant ML350e Gen8 Server
HPE ProLiant ML310e Gen8 v2 Server
HPE ProLiant ML310e Gen8 Server
HPE Apollo r2000 Chassis
HPE Apollo 6500 Gen10 Plus System
HPE Apollo 6500 Gen10 System
HPE Apollo 4510 Gen10 System
HPE Apollo 4200 Gen10 Plus System
HPE Apollo 4200 Gen10 Server
HPE Apollo n2800 Gen10 Plus
HPE Apollo r2800 Gen10 24 SFF Flexible Configure-to-order Chassis
HPE Apollo n2600 Gen10 Plus
HPE Apollo r2600 Gen10 24 SFF Premium Configure-to-order Chassis
HPE Apollo r2200 Gen10 12 LFF Configure-to-order Chassis
HPE ProLiant ML30 Gen9 Server
HPE ProLiant BL660c Gen9 Server
HPE ProLiant BL660c Gen8 Server Blade
HPE ProLiant BL465c Gen8 Server Blade
HPE ProLiant BL460c Gen9 Server Blade
HPE ProLiant BL460c Gen8 Server Blade
HPE ProLiant BL420c Gen8 Server
HPE ProLiant DL580 Gen9 Server
HPE ProLiant DL580 Gen8 Server
HPE ProLiant DL560 Gen9 Server
HPE ProLiant DL560 Gen8 Server
HPE StoreEasy 3850 Gateway Storage Blade
HPE 3PAR StoreServ File Controller
HPE 3PAR StoreServ File Controller v2 Storage
HPE 3PAR StoreServ File Controller v3 System
HPE StoreEasy 1450 Storage
HPE StoreEasy 1550 Storage
HPE StoreEasy 1650 Expanded Storage
HPE StoreEasy 1650 Storage
HPE StoreEasy 1850 Storage
HPE StoreEasy 3850 Gateway Single Node Upgrade
HPE StoreEasy 3850 Gateway Storage
HPE Apollo 4200 Gen9 Server
HPE StoreVirtual 3000 File Controller
HPE StoreEasy 1430 Storage
HPE StoreEasy 1440 Storage
HPE StoreEasy 1530 Storage
HPE StoreEasy 1540 Storage
HPE StoreEasy 1630 Storage
HPE StoreEasy 1640 Storage
HPE StoreEasy 1830 Storage
HPE StoreEasy 1840 Storage
HPE StoreEasy 3830 Gateway Storage
HPE ProLiant XL250a Gen9 Server
HPE ProLiant SL270s Gen8 Server
HPE ProLiant SL270s Gen8 SE Server
HPE ProLiant SL250s Gen8 Server
HPE ProLiant SL230s Gen8 Server
HPE ProLiant SL210t Gen8 Server
HPE ProLiant XL750f Gen9 Server
HPE ProLiant XL740f Gen9 Server
HPE ProLiant XL730f Gen9 Server
HPE ProLiant XL450 Gen9 Server
HPE ProLiant XL270d Gen9 Special Server
HPE Edgeline e920t Server Blade
HPE ProLiant XL230a Gen9 Server
HPE ProLiant XL230b Gen9 Server
HPE ProLiant XL220a Gen8 v2 Server
HPE ProLiant XL190r Gen9 Server
HPE ProLiant XL170r Gen9 Server
HPE ProLiant ML110 Gen9 Server
HPE ProLiant MicroServer Gen8
HPE ProLiant WS460c Gen9 Graphics Server Blade
HPE ProLiant WS460c Gen8 Graphics Server Blade
HPE ProLiant DL385 Gen10 Server
IBM Power System IC922
HP ConvergedSystem 700
HP ConvergedSystem 700x
HPE ProLiant BL460c Gen10 Server Blade
HPE ProLiant DL580 Gen10 Server
HPE ProLiant DL560 Gen10 Server
HPE ProLiant DL385 Gen10 Plus server
HPE ProLiant DL385 Gen10 Plus v2 server
HPE ProLiant DL380 Gen10 Plus server
HPE ProLiant DL380 Gen10 Server
HPE ProLiant DL365 Gen10 Plus server
HPE ProLiant DL360 Gen10 Plus server
HPE ProLiant DL360 Gen10 Server
HPE ProLiant DL345 Gen10 Plus server
HPE ProLiant DL325 Gen10 Plus server
HPE ProLiant DL325 Gen10 Server
HPE ProLiant DL180 Gen10 Server
HPE ProLiant DL160 Gen10 Server
HPE ProLiant XL290n Gen10 Plus Server
HPE StoreEasy 1460 Storage
HPE StoreEasy 1560 Storage
HPE StoreEasy 1660 Expanded Storage
HPE StoreEasy 1660 Performance Storage
HPE StoreEasy 1660 Storage
HPE StoreEasy 1860 Performance Storage
HPE StoreEasy 1860 Storage
HPE ProLiant XL675d Gen10 Plus Server
HPE ProLiant XL645d Gen10 Plus Server
HPE ProLiant XL450 Gen10 Server
HPE Storage Performance File Controller
HPE ProLiant XL270d Gen10 Server
HPE ProLiant XL230k Gen10 Server
HPE ProLiant XL225n Gen10 Plus 1U Node
HPE ProLiant XL220n Gen10 Plus Server
HPE ProLiant XL190r Gen10 Server
HPE ProLiant XL170r Gen10 Server
HPE ProLiant e910 Server Blade
HPE ProLiant e910t Server Blade
HPE Edgeline e920 Server Blade
HPE Edgeline e920d Server Blade
HPE ProLiant DX380 Gen10 server
HPE ProLiant DL120 Gen10 Server
HPE ProLiant DL20 Gen10 Plus server
HPE ProLiant DL20 Gen10 Server
HPE ProLiant DX170r Gen10 server
HPE ProLiant DX190r Gen10 server
HPE ProLiant DX220n Gen10 Plus server
HPE ProLiant DX325 Gen10 Plus v2 server
HPE ProLiant DX360 Gen10 Plus server
HPE ProLiant DX360 Gen10 server
HPE ProLiant DX380 Gen10 Plus server
HPE ProLiant DX385 Gen10 Plus v2 server
HPE ProLiant DX385 Gen10 Plus server
HPE ProLiant DX560 Gen10 server
HPE ProLiant DX4200 Gen10 server
HPE ProLiant ML350 Gen10 Server
HPE ProLiant ML110 Gen10 Server
HPE ProLiant ML30 Gen10 Plus server
HPE ProLiant ML30 Gen10 Server
HPE Storage File Controller
HPE StoreEasy 3840 Gateway Storage
HPE StoreEasy 3840 Gateway Storage Blade
HPE StoreEasy 3830 Gateway Storage Blade
BIG-IP
IBM Power System AC922
Inspiron 3521
HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers
HPE Integrated Lights-Out 4 (iLO 4)
Virtualization Engine TS7700 3957-VED
Virtualization Engine TS7700 3957-VEC
PowerScale OneFS
My Cloud EX2100
WD Cloud
My Cloud DL4100
My Cloud EX2 Ultra
My Cloud DL2100
My Cloud Mirror G2
My Cloud EX4100
My Cloud PR4100
My Cloud PR2100
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
My Cloud
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
SUSE Enterprise Storage
FortiOS
Anolis OS
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
CentOS
IBM Security Identity Manager Virtual Appliance
IBM AIX
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Oracle Linux
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Palo Alto PAN-OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Brocade Fabric OS
Oracle Solaris
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Manager Tools
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
FreeBSD
Slackware Linux
Ubuntu
openSUSE Leap
Junos OS
openEuler
Junos OS Evolved
Arista Extensible Operating System (EOS)
My Cloud OS 5
MELSOFT iQ AppPortal
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
IBM Edge Application Manager
Traffix SDC
IBM Spectrum Protect Backup-Archive Client
VMware Horizon Client
IBM Engineering Requirements Quality Assistant
Edgecross Basic Software for Windows ECP-BS1-W
Edgecross Basic Software for Developers ECP-BS1-W-D
cflinuxfs3
Telemetry Dashboard
Security Verify Bridge Docker
Oracle Enterprise Communications Broker
Oracle Communications Operations Monitor
DataStage on Cloud Pak for Data
RecoverPoint Classic
Dell Policy Manager for Secure Connect Gateway (SCG)
PowerPath Windows
Liquidware
Oracle Enterprise Session Border Controller
IBM MQ Appliance
IceWall Gen11 certd module for RHEL
Avamar Virtual Edition
Citrix Workspace App
Webex App VDI
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Db2 Rest
Storage Defender – Data Protect
Dell Client Agent Enabler
Sterling Connect:Express for UNIX
Dell Hybrid Client
Dell DataIQ
IBM Sterling Connect:Direct for HP NonStop
Dell Wyse Management Suite
EMC ECS
IBM Cloud Pak for Watson AIOps
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
PowerVault ME5024
PowerVault ME5084
PowerVault ME5012
Aruba Fabric Composer
XtremIO X2
Dell EMC NetWorker Runtime Environment (NRE)
MobileFirst Platform
Dell EMC OS9
EMC Cloud Tiering Appliance
Integrated System for Microsoft Azure Stack Hub
IBM Business Process Manager
IBM Security Verify Bridge
Service Telemetry Framework
IBM Cloud Transformation Advisor
Dell PowerPath Management Appliance
Oracle VM Server for x86
IBM Cloud Object Storage Systems
Red Hat Advanced Cluster Security for Kubernetes
EasyApache
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM IoT MessageSight
IBM WIoTP MessageGateway
Dell Secure Connect Gateway
OpenShift Logging
IBM Sterling Connect:Direct for UNIX
IBM Rational Build Forge
PowerPath Linux
IBM MQ for HPE NonStop
Tenable Nessus
IBM Rational ClearQuest
IBM Workload Scheduler
IBM Integration Bus
IBM QRadar WinCollect Agent
IBM Security Verify Governance
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Netcool Operations Insight
IBM Cloud Pak for Multicloud Management Monitoring
Red Hat Advanced Cluster Management for Kubernetes
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
Session Smart Router
IBM Safer Payments
PowerProtect Data Domain
Steel Belted Radius Carrier Edition
InfoSphere Master Data Management
IBM InfoSphere Information Server for Cloud
Dell EMC Data Protection Search
EMC NetWorker Server
NetWorker
PowerProtect Data Manager
MicroSCADA Pro SYS600
MicroSCADA X SYS600
GT SoftGOT2000
Silver Peak Orchestrator
FortiSwitch
FortiProxy
RAX30
Dell EMC VxRail Appliance
AirWave Management Platform
Gaia
PowerVM Hypervisor
Tenable.sc
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
elfutils (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
openssl (Red Hat package)
openssl (Debian package)
imgbased (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
jbcs-httpd24-curl (Red Hat package)
openssl-debugsource
openssl-debuginfo
libopenssl-devel
libopenssl0_9_8-32bit
openssl-doc
openssl
libopenssl0_9_8-hmac
libopenssl0_9_8
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo-32bit
libopenssl0_9_8-debuginfo
compat-openssl098-debugsource
libopenssl1_0_0
libopenssl1-devel
openssl1
openssl1-doc
libopenssl1_0_0-32bit
libopenssl1_0_0-x86
libssl1.0.0 (Ubuntu package)
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
libopenssl1_0_0-hmac
libopenssl1_0_0-hmac-32bit
openssl-static
openssl-perl
openssl-devel
openssl-libs
compat-openssl10
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-doc
openssl-1_0_0-debugsource
openssl-1_0_0-debuginfo
openssl-1_0_0
libopenssl-1_0_0-devel
libopenssl10-debuginfo
libopenssl10
libopenssl1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
openssl-1_1-debuginfo
openssl-1_1-debugsource
libopenssl-1_1-devel
libopenssl1_1
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-help
openssl11
compat-openssl11 (Red Hat package)
openssl1.1
dev-libs/openssl
libssl1.1 (Ubuntu package)
zlib-debugsource
libz1-debuginfo
libz1
jws5-tomcat-native (Red Hat package)
intel-sgx-ssl
intel-sgx-ssl-devel
libsgx-launch
linux-sgx-debugsource
linux-sgx-debuginfo
libsgx-aesm-epid-plugin
libsgx-ae-epid
libsgx-quote-ex-devel
linux-sgx
libsgx-dcap-quote-verify
libsgx-ra-network-devel
libsgx-launch-devel
libsgx-enclave-common
libsgx-aesm-quote-ex-plugin
libsgx-epid-devel
libsgx-ra-network
libsgx-uae-service
libsgx-urts
libsgx-quote-ex
sgxsdk
libsgx-dcap-ql
libsgx-enclave-common-devel
libsgx-aesm-launch-plugin
sgx-aesm-service
sgx-pck-id-retrieval-tool
libsgx-ra-uefi-devel
libsgx-ae-pce
libsgx-dcap-ql-devel
libsgx-dcap-default-qpl-devel
libsgx-ae-le
libsgx-pce-logic
libsgx-dcap-default-qpl
libsgx-ae-qe3
libsgx-aesm-pce-plugin
libsgx-epid
libsgx-ra-uefi
libsgx-qe3-logic
libsgx-dcap-quote-verify-devel
libsgx-aesm-ecdsa-plugin
sgx-ra-service
sgx-dcap-pccs
libsgx-ae-qve
glibc-locale
glibc-debugsource
glibc-locale-base
glibc-debuginfo
glibc
glibc-locale-base-debuginfo
openssl3
redhat-virtualization-host-productimg (Red Hat package)
ovirt-node-ng (Red Hat package)
libxcrypt-debugsource
libcrypt1-debuginfo
libcrypt1
jws5-tomcat (Red Hat package)
mariadb-debuginfo
mariadb
mariadb-server
mariadb-server-galera
mariadb-debugsource
mariadb-gssapi-server
mariadb-embedded
mariadb-test
mariadb-oqgraph-engine
mariadb-cracklib
mariadb-errmessage
mariadb-common
mariadb-embedded-devel
mariadb-backup
mariadb-devel
mariadb105
libnode-dev (Ubuntu package)
libnode72 (Ubuntu package)
nodejs (Ubuntu package)
nodejs-doc (Ubuntu package)
npm12
nodejs12-docs
nodejs12-devel
nodejs12-debuginfo
nodejs12
nodejs12-debugsource
nodejs14-docs
npm14
nodejs14-devel
nodejs14-debugsource
nodejs14-debuginfo
nodejs14
corepack14
shim-debugsource
shim
shim-debuginfo
edk2 (Ubuntu package)
venv-salt-minion
edk2-aarch64
edk2-devel
edk2-debugsource
edk2-debuginfo
edk2
edk2-help
edk2-ovmf
python3-edk2-devel
python-ecdsa
Open Enclave SDK
MySQL Workbench
IBM App Connect Enterprise
Engineering Lifecycle Management
Voice Gateway
Cisco Webex Meetings
Harbor
Red Hat Virtualization
OpenShift Virtualization
Oracle GraalVM Enterprise Edition
Red Hat OpenShift Serverless
IBM Netezza Host Management
IBM Spectrum Virtualize
Cloud Pak for Security (CP4S)
Securepoint SSL VPN Client
FortiDeceptor
FortiAuthenticator
IBM Qradar SIEM
Event Streams
IBM Cloud Pak System
JBoss Core Services
IBM VIOS
Red Hat Virtualization Host
Dell EMC AppSync
iDRAC8
iDRAC9
Dell EMC NetWorker vProxy
FortiMail
FortiManager
FortiAnalyzer
EMC Integrated Data Protection Appliance
RecoverPoint for VMs
IBM QRadar Network Security
IBM QRadar Network Packet Capture
JBoss Web Server
MySQL Server
MySQL Enterprise Monitor
IBM InfoSphere Information Server
FortiRecorder
FortiWeb
Oracle Communications Session Border Controller
Orion Platform
IBM Hardware Management Console
IBM Security Verify Access
Juniper Junos Space
IBM DS8000 Hardware Management Console
MySQL Connectors
Oracle Communications Core Session Manager
Oracle Communications Unified Session Manager
SecurID Authentication Manager
Zimbra Collaboration
IceWall Gen11 certd module for Windows
IBM Security Guardium
Cisco Jabber
IBM MaaS360 VPN Module
IBM Cognos Analytics
How to mitigate CVE-2022-0778
IBM Power System IC922 - update to OP940.40
MELSOFT iQ AppPortal - update to 1.29F
MicroSCADA Pro SYS600 - update to 10.4
MicroSCADA X SYS600 - update to 10.4
Edgecross Basic Software for Windows ECP-BS1-W - update to 1.27
Edgecross Basic Software for Developers ECP-BS1-W-D - update to 1.27
PowerVM Hypervisor - addressed in versions FW950.40, FW1010.32
Tenable.sc - addressed in versions Patch 202204.1, 5.21.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-26.el8jbcs, 0.4.10-26.jbcs.el7
python-ecdsa - update to 0.18.0
Open Enclave SDK - update to 0.17.7
elfutils (Red Hat package) - update to 0.186-1.el8
cflinuxfs3 - update to 0.278.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-11.el8jbcs, 1.0.0-11.jbcs.el7
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Red Hat package) - addressed in versions 1.0.1e-60.el6_10, 1.0.1e-62.el7_3, 1.0.2k-10.el7_4, 1.0.2k-18.el7_6, 1.0.2k-21.el7_7, 1.0.2k-25.el7_9, 1.1.1c-5.el8_1.1, 1.1.1c-19.el8_2, 1.1.1g-16.el8_4, 1.1.1k-6.el8_5
Voice Gateway - update to 1.0.7.12
openssl (Debian package) - addressed in versions 1.1.1k-1+deb11u2, 1.1.1d-0+deb10u8
imgbased (Red Hat package) - update to 1.2.24-1.el8ev
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-91.el8jbcs, 1.6.1-91.jbcs.el7
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.1, 1.7.3
Harbor - update to 1.10.11
Cloud Pak for Security (CP4S) - update to 1.10.7.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-22.el8jbcs, 1.15.7-22.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-41.el8jbcs, 1.39.2-41.jbcs.el7
GT SoftGOT2000 - update to 1.280S
IBM Cloud Transformation Advisor - update to 3.2.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-41.el8jbcs, 2.0.8-41.jbcs.el7
Securepoint SSL VPN Client - update to 2.0.37
IBM Cloud Pak System - update to 2.3.3.5
JBoss Core Services - update to 2.4.37 SP11
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-80.el8jbcs, 2.4.37-80.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-68.GA.el8jbcs, 2.9.2-68.GA.jbcs.el7
Red Hat Advanced Cluster Security for Kubernetes - update to 3.68.2
EasyApache - addressed in versions 4 2022-3-17, 4 2022-3-23, 4 2022-5-11
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
Dell EMC NetWorker vProxy - update to 4.3.0-20
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.22-1.el7ev, 4.5.0-5.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.22-20220330.1.el7_9
Dell EMC AppSync - update to 4.4.1.0_3996_R1
Red Hat OpenShift Container Platform - addressed in versions 4.6.57, 4.8.37, 4.9.29, 4.10.10, 4.11.0
DataStage on Cloud Pak for Data - update to 5.0.0
OpenShift Virtualization - addressed in versions 4.9.4, 4.10.1, 4.11.0
Nessus Network Monitor - update to 6.0.1
IBM WIoTP MessageGateway - update to 5.0.0.2
Dell Secure Connect Gateway - addressed in versions 5.12.00.10, 5.28.00.14
RecoverPoint Classic - update to 5.1 SP4 P4
OpenShift Logging - addressed in versions 5.2.10, 5.3.7, 5.4.1
RecoverPoint for VMs - update to 5.3.3.1
IBM QRadar Network Security - addressed in versions 5.4.0.16, 5.5.0.11
JBoss Web Server - update to 5.6.2
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.12.00.00
FortiAuthenticator - update to 6.4.2
FortiSwitch - addressed in versions 6.4.11, 7.0.5, 7.2.0
IBM Sterling Connect:Direct for UNIX - update to 6.2.0.4
FortiOS - addressed in versions 6.4.9, 7.2.0
FortiWeb - update to 6.3.19
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.24
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 12, 7.4.3 Fix Pack 6, 7.5.0 Update Pack 2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-3.el8jbcs, 7.78.0-3.jbcs.el7
IBM Spectrum Protect Backup-Archive Client - update to 8.1.15
IBM MQ for HPE NonStop - update to 8.1.0.10
Palo Alto PAN-OS - addressed in versions 8.1.23, 9.0.16-hf, 9.1.13-hf, 10.0.10, 10.1.5-hf, 10.2.1
SecurID Authentication Manager - update to 8.6 Patch 3
Zimbra Collaboration - addressed in versions 8.8.15 Patch 32, 9.0.0 Patch 25
Tenable Nessus - addressed in versions 8.15.4, 10.1.2
IBM Rational ClearQuest - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
Brocade Fabric OS - addressed in versions 9.0.1e, 9.1.1
IBM MQ Appliance - update to 9.2.0.6
IBM Workload Scheduler - addressed in versions 9.4.0.7, 9.5.0.6
Event Streams - update to 11.0.0
IBM QRadar WinCollect Agent - update to 10.0.2
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Spectrum Protect Plus - addressed in versions 10.1.11, 10.1.12
macOS - addressed in versions 10.15.7 19H1922, 11.6.6 20G624, 12.4 21F79
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Junos OS - addressed in versions 18.4R2-S10, 18.4R3-S10, 19.1R3-S7, 19.1R3-S9, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.3R3-S6, 19.4R2-S6, 19.4R2-S7, 19.4R3-S6, 19.4R3-S9, 20.1R3-S3, 20.1R3-S4, 20.2R3-S3, 20.2R3-S5, 20.3R3-S3, 20.3R3-S4, 20.4R3, 20.4R3-S4, 21.1R2, 21.1R3-S3, 21.2R1, 21.2R3-S1, 21.3R3-S1, 21.4R2, 22.1R2, 22.2R1
Junos OS Evolved - addressed in versions 22.1R3-EVO, 22.2R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
Orion Platform - update to 2024.2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-7, 2022.2.1-0
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-7, 2021.4.1-2
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
IBM Hardware Management Console - addressed in versions OP940.40, 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc
IBM Power System AC922 - update to OP940.40
openssl-debugsource - addressed in versions 0.9.8j-0.106.46.1, 1.0.2j-60.75.1
openssl-debuginfo - addressed in versions 0.9.8j-0.106.46.1, 1.0.2j-60.75.1
libopenssl-devel - addressed in versions 0.9.8j-0.106.46.1, 1.0.2j-60.75.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.46.1, 0.9.8j-106.33.1
openssl-doc - addressed in versions 0.9.8j-0.106.46.1, 1.0.2j-60.75.1
openssl - addressed in versions 0.9.8j-0.106.46.1, 1.0.2j-60.75.1
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.46.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.46.1, 0.9.8j-106.33.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.46.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.33.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.33.1
compat-openssl098-debugsource - update to 0.9.8j-106.33.1
Red Hat OpenShift Serverless - update to 1
Db2 Rest - update to 1.0.0.304
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.42.1, 1.0.2j-60.75.1, 1.0.2p-3.48.1, 1.0.2p-3.49.1
libopenssl1-devel - update to 1.0.1g-0.58.42.1
openssl1 - update to 1.0.1g-0.58.42.1
openssl1-doc - update to 1.0.1g-0.58.42.1
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.42.1, 1.0.2j-60.75.1, 1.0.2p-3.48.1
libopenssl1_0_0-x86 - update to 1.0.1g-0.58.42.1
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm5, 1.0.2g-1ubuntu4.20+esm2, 1.0.2n-1ubuntu5.8
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.75.1, 1.0.2p-3.48.1, 1.0.2p-3.49.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.75.1, 1.0.2p-3.48.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.75.1, 1.0.2p-3.48.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.75.1, 1.0.2p-3.48.1
openssl-static - update to 1.0.2k-25
openssl-perl - addressed in versions 1.0.2k-25, 1.1.1k-5.0.2
openssl - addressed in versions 1.0.2k-25, 1.1.1k-5.0.2
openssl-devel - addressed in versions 1.0.2k-25, 1.1.1k-5.0.2
openssl-libs - addressed in versions 1.0.2k-25, 1.1.1k-5.0.2
compat-openssl10 - update to 1.0.2o-4.0.1
libopenssl-1_0_0-devel-32bit - update to 1.0.2p-3.48.1
openssl-1_0_0-doc - update to 1.0.2p-3.48.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.48.1, 1.0.2p-3.49.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.48.1, 1.0.2p-3.49.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.48.1, 1.0.2p-3.49.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.48.1, 1.0.2p-3.49.1
libopenssl10-debuginfo - update to 1.0.2p-3.49.1
libopenssl10 - update to 1.0.2p-3.49.1
RAX30 - update to 1.0.9.92
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
openssl-1_1 - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
libopenssl1_1 - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1, 1.1.1d-11.43.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-4.66.1, 1.1.0i-14.27.1, 1.1.1d-2.61.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-14.27.1, 1.1.1d-2.61.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.61.1
openssl-libs - update to 1.1.1f-15
openssl - update to 1.1.1f-15
openssl-debuginfo - update to 1.1.1f-15
openssl-help - update to 1.1.1f-15
openssl-debugsource - update to 1.1.1f-15
openssl-devel - update to 1.1.1f-15
openssl11 - update to 1.1.1k-3.el7
compat-openssl11 (Red Hat package) - update to 1.1.1k-4.el9_0
openssl - addressed in versions 1.1.1n-1.fc34, 1.1.1n-1.fc35
openssl1.1 - addressed in versions 1.1.1n-1.fc36, 1.1.1n-1.fc37
dev-libs/openssl - update to 1.1.1q
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.2, 1.1.1f-1ubuntu2.12, 1.1.1-1ubuntu2.1~18.04.15
zlib-debugsource - update to 1.2.11-3.26.10
libz1-debuginfo - update to 1.2.11-3.26.10
libz1 - update to 1.2.11-3.26.10
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.30-4.redhat_4.el7jws, 1.2.30-4.redhat_4.el8jws
Storage Defender – Data Protect - update to 1.4.0
Dell Client Agent Enabler - update to 1.4.1
Sterling Connect:Express for UNIX - update to 1.5.0.1609
Dell Hybrid Client - addressed in versions 1.6, 1.6.1, 1.6.2
Netcool Operations Insight - update to 1.6.8
Inspiron 3521 - update to 1.9.0
Dell DataIQ - update to 2.2.2.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.3, 2.5.0
EMC Integrated Data Protection Appliance - update to 2.7.3
intel-sgx-ssl - update to 2.10-4
intel-sgx-ssl-devel - update to 2.10-4
libsgx-launch - update to 2.11.100-11
linux-sgx-debugsource - update to 2.11.100-11
linux-sgx-debuginfo - update to 2.11.100-11
libsgx-aesm-epid-plugin - update to 2.11.100-11
libsgx-ae-epid - update to 2.11.100-11
libsgx-quote-ex-devel - update to 2.11.100-11
linux-sgx - update to 2.11.100-11
libsgx-dcap-quote-verify - update to 2.11.100-11
libsgx-ra-network-devel - update to 2.11.100-11
libsgx-launch-devel - update to 2.11.100-11
libsgx-enclave-common - update to 2.11.100-11
libsgx-aesm-quote-ex-plugin - update to 2.11.100-11
libsgx-epid-devel - update to 2.11.100-11
libsgx-ra-network - update to 2.11.100-11
libsgx-uae-service - update to 2.11.100-11
libsgx-urts - update to 2.11.100-11
libsgx-quote-ex - update to 2.11.100-11
sgxsdk - update to 2.11.100-11
libsgx-dcap-ql - update to 2.11.100-11
libsgx-enclave-common-devel - update to 2.11.100-11
libsgx-aesm-launch-plugin - update to 2.11.100-11
sgx-aesm-service - update to 2.11.100-11
sgx-pck-id-retrieval-tool - update to 2.11.100-11
libsgx-ra-uefi-devel - update to 2.11.100-11
libsgx-ae-pce - update to 2.11.100-11
libsgx-dcap-ql-devel - update to 2.11.100-11
libsgx-dcap-default-qpl-devel - update to 2.11.100-11
libsgx-ae-le - update to 2.11.100-11
libsgx-pce-logic - update to 2.11.100-11
libsgx-dcap-default-qpl - update to 2.11.100-11
libsgx-ae-qe3 - update to 2.11.100-11
libsgx-aesm-pce-plugin - update to 2.11.100-11
libsgx-epid - update to 2.11.100-11
libsgx-ra-uefi - update to 2.11.100-11
libsgx-qe3-logic - update to 2.11.100-11
libsgx-dcap-quote-verify-devel - update to 2.11.100-11
libsgx-aesm-ecdsa-plugin - update to 2.11.100-11
sgx-ra-service - update to 2.11.100-11
sgx-dcap-pccs - update to 2.11.100-11
libsgx-ae-qve - update to 2.11.100-11
glibc-locale - update to 2.31-150300.20.7
glibc-debugsource - update to 2.31-150300.20.7
glibc-locale-base - update to 2.31-150300.20.7
glibc-debuginfo - update to 2.31-150300.20.7
glibc - update to 2.31-150300.20.7
glibc-locale-base-debuginfo - update to 2.31-150300.20.7
HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers - update to 2.72
HPE Integrated Lights-Out 4 (iLO 4) - update to 2.81
iDRAC8 - update to 2.83.83.83
IBM MaaS360 Mobile Enterprise Gateway - update to 2.106.500
IBM MaaS360 VPN Module - update to 2.106.500
IBM MaaS360 Cloud Extender Agent - update to 2.106.500.011
openssl3 - update to 3.0.1-18.el8.1
openssl - update to 3.0.5-1
IBM Sterling Connect:Direct for HP NonStop - update to 3.6.0.3 iFix 002
Dell Wyse Management Suite - update to 3.6.1
EMC ECS - update to 3.7.0.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
redhat-virtualization-host-productimg (Red Hat package) - addressed in versions 4.3.22-1.el7, 4.5.0-2.el8
ovirt-node-ng (Red Hat package) - update to 4.4.2-1.el8ev
libxcrypt-debugsource - update to 4.4.15-150300.4.2.41
libcrypt1-debuginfo - update to 4.4.15-150300.4.2.41
libcrypt1 - update to 4.4.15-150300.4.2.41
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Arista Extensible Operating System (EOS) - addressed in versions 4.23.12, 4.24.10, 4.25.9, 4.26.6, 4.27.4
PowerVault ME5024 - update to 5.1.1.0.5
PowerVault ME5084 - update to 5.1.1.0.5
PowerVault ME5012 - update to 5.1.1.0.5
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Session Smart Router - addressed in versions 5.4.7, 5.5.3
IBM Netezza Host Management - update to 5.4.32.0
iDRAC9 - update to 5.10.30.00
My Cloud OS 5 - addressed in versions 5.22.113, 5.23.114
IBM Safer Payments - addressed in versions 6.1.1.01, 6.2.2.01, 6.3.1.01, 6.4.2.00
Aruba Fabric Composer - update to 6.2.1
XtremIO X2 - update to 6.4.1-11
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Dell EMC VxRail Appliance - update to 7.0.372
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
IBM Spectrum Virtualize - addressed in versions 7.8.1.15, 8.2.1.16, 8.3.1.7, 8.4.0.9, 8.5.0.1, 8.5.2.0
Dell EMC NetWorker Runtime Environment (NRE) - update to 8.0.13
MobileFirst Platform - addressed in versions 8.0.2022042909, 8.0.2022050611, 8.0.2022050908
AirWave Management Platform - update to 8.2.14.1
Steel Belted Radius Carrier Edition - update to 8.6.0R16
Virtualization Engine TS7700 3957-VED - addressed in versions 8.50.2.6 VTD_EXEC.279, 8.51.2.12 VTD_EXEC.279, 8.52.101.12 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.50.2.6 VTD_EXEC.279, 8.51.2.12 VTD_EXEC.279, 8.52.101.12 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279
jws5-tomcat (Red Hat package) - addressed in versions 9.0.50-5.redhat_00007.1.el7jws, 9.0.50-5.redhat_00007.1.el8jws
Dell EMC OS9 - addressed in versions 9.14.1.12, 9.14.2.14
IBM Security Verify Access - update to 10.0.7.0
mariadb-debuginfo - update to 10.3.39-1
mariadb - update to 10.3.39-1
mariadb-server - update to 10.3.39-1
mariadb-server-galera - update to 10.3.39-1
mariadb-debugsource - update to 10.3.39-1
mariadb-gssapi-server - update to 10.3.39-1
mariadb-embedded - update to 10.3.39-1
mariadb-test - update to 10.3.39-1
mariadb-oqgraph-engine - update to 10.3.39-1
mariadb-cracklib - update to 10.3.39-1
mariadb-errmessage - update to 10.3.39-1
mariadb-common - update to 10.3.39-1
mariadb-embedded-devel - update to 10.3.39-1
mariadb-backup - update to 10.3.39-1
mariadb-devel - update to 10.3.39-1
mariadb105 - update to 10.5.16-1
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
PowerScale OneFS - addressed in versions 11.7, 12.0
IBM InfoSphere Information Server for Cloud - update to 11.7.1.4
libnode-dev (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs-doc (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
npm12 - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
nodejs12-docs - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
nodejs12-devel - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
nodejs12-debuginfo - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
nodejs12 - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
nodejs12-debugsource - addressed in versions 12.22.11-1.45.1, 12.22.12-150200.4.32.1
EMC Cloud Tiering Appliance - addressed in versions 13.0.0.2.31, 13.1.0.2.22
nodejs14-docs - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
npm14 - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
nodejs14-devel - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
nodejs14-debugsource - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
nodejs14-debuginfo - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
nodejs14 - addressed in versions 14.19.1-6.28.1, 14.19.1-150200.15.31.1
corepack14 - update to 14.19.1-150200.15.31.1
shim-debugsource - update to 15-23
shim - update to 15-23
shim-debuginfo - update to 15-23
Dell EMC Data Protection Search - update to 19.6.1
EMC NetWorker Server - update to 19.7.0.0
NetWorker - update to 19.10.0.0
PowerProtect Data Manager - update to 19.19.0-15
Juniper Junos Space - update to 22.2R1
Gaia - update to R81.10 Take 44
IBM DS8000 Hardware Management Console - update to 89.30.68.0
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
Integrated System for Microsoft Azure Stack Hub - update to 2207
venv-salt-minion - update to 3004-3.9.1
edk2-aarch64 - addressed in versions 202002-24, 202011-20
edk2-devel - addressed in versions 202002-24, 202011-20
edk2-debugsource - addressed in versions 202002-24, 202011-20
edk2-debuginfo - addressed in versions 202002-24, 202011-20
edk2 - addressed in versions 202002-24, 202011-20
edk2-help - addressed in versions 202002-24, 202011-20
edk2-ovmf - addressed in versions 202002-24, 202011-20
python3-edk2-devel - addressed in versions 202002-24, 202011-20
Links to Public Exploits and PoC-codes
- Exploit #7676 - CVE-2022-0778 (Proof of concept for CVE-2022-0778 in P12 and PEM format) (April 21, 2022)
- Exploit #7662 - CVE-2022-0778-POC () (April 18, 2022)
- Exploit #7596 - cve-2022-0778 () (April 5, 2022)
- Exploit #7503 - CVE-2022-0778 (Proof of concept for CVE-2022-0778, which triggers an infinite loop in parsing X.509 certificates due to a bug in BN_mod_sqrt) (March 16, 2022)
External References
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=380085481c64de749a6dd25cdf0bcf4360b30f83
- https://www.openssl.org/news/secadv/20220315.txt
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a466912611aa6cbdf550cd10601390e587451246
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65
Related Security Bulletins
- Denial of service in OpenSSL
- FreeBSD update for OpenSSL
- Debian update for openssl
- Ubuntu update for openssl
- Ubuntu update for openssl
- Amazon Linux AMI update for openssl
- Denial of service in Cloud Foundry cflinuxfs3
- Slackware Linux update for openssl
- cPanel EasyApache 4 update for OpenSSL
- cPanel EasyApache 4 update for OpenSSL (ea-nodejs16)
- Red Hat Enterprise Linux 7.3 update for openssl
- Red Hat Enterprise Linux 7.6 update for openssl
- Red Hat Enterprise Linux 7.7 update for openssl
- Red Hat Enterprise Linux 7.4 update for openssl
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for openssl
- Red Hat Enterprise Linux 8.4 update for openssl
- Red Hat Enterprise Linux 7 update for openssl
- Red Hat Enterprise Linux 8 update for openssl
- Denial of service in F5 BIG-IP control panel and TMM (OpenSSL component)
- Denial of service in Traffix SDC (OpenSSL component)
- Red Hat Enterprise Linux 8.2 update for openssl
- CentOS 7 update for openssl
- Red Hat Enterprise Linux 8.1 update for openssl
- Palo Alto PAN-OS update for OpenSSL
- Nessus update for OpenSSL
- Denial of service in FortiOS OpenSSL library
- Denial of service in FortiManager OpenSSL library
- Denial of service in FortiAnalyzer OpenSSL library
- Multiple vulnerabilities in openvpn-client
- Denial of service in FortiDeceptor OpenSSL library
- Denial of service in FortiAuthenticator OpenSSL library
- Denial of service in FortiMail OpenSSL library
- Denial of service in FortiRecorder OpenSSL library
- Denial of service in FortiProxy OpenSSL library
- Denial of service in FortiSwitch OpenSSL library
- Denial of service in FortiWeb OpenSSL library
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Red Hat Virtualization
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Infinite loop in MySQL Workbench
- Multiple vulnerabilities in MySQL Server
- Infinite loop in MySQL Connectors
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Red Hat JBoss Core Services
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Multiple vulnerabilities in OpenShift Container Platform 4.10
- Denial of service in Dell PowerPath OpenSSL component
- Multiple vulnerabilities in Dell EMC NetWorker vProxy
- Denial of service in Open Enclave SDK
- Multiple vulnerabilities in JBoss Web Server
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in Red Hat OpenShift Logging
- Multiple vulnerabilities in Mitsubishi Electric MELSOFT iQ AppPortal
- Multiple vulnerabilities in Harbor
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple macOS Catalina
- IBM Cloud Object Storage Systems update for OpenSSL
- Multiple vulnerabilities in Western Digital My Cloud OS 5
- Multiple vulnerabilities in Red Hat Virtualization 4 for RHEL 8
- Red Hat Enterprise Linux 9 update for compat-openssl11
- Denial of service in IBM Netezza Host Management
- Denial of service in IBM Hardware Management Console
- Multiple vulnerabilities in IBM WIoTP MessageGateway/IoT MessageSight
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Multiple vulnerabilities in IBM DS8000 Hardware Management Console
- Denial of service in IBM InfoSphere Information Server
- Denial of service in IBM App Connect Enterprise & IBM Integration Bus
- Multiple vulnerabilities in IBM Security Identity Manager Virtual Appliance
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Denial of service in IBM Spectrum Protect Backup-Archive Client
- Red Hat Enterprise Linux 8 update for compat-openssl10
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Infinite loop in IBM QRadar Network Security
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Denial of service in python-ecdsa
- Infinite loop in IBM MQ for HPE NonStop
- Infinite loop in IBM Event Streams
- Infinite loop in IBM MQ Appliance
- Infinite loop in IBM PowerVM Hypervisor
- Multiple vulnerabilites in IBM Engineering Requirements Quality Assistant
- Infinite loop in Oracle Enterprise Session Border Controller
- Infinite loop in Oracle Enterprise Communications Broker
- Infinite loop in Oracle Communications Unified Session Manager
- Infinite loop in Oracle Communications Session Border Controller
- Infinite loop in Oracle Communications Core Session Manager
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Western Digital My Cloud OS 5
- Multiple vulnerabilities in IBM Rational ClearQuest
- Denial of service in IBM QRadar SIEM
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in Dell AppSync
- Denial of service in IBM Security Verify Bridge Docker image
- Multiple vulnerabilities in Dell Policy Manager for Secure Connect Gateway
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Denial of service in IBM Sterling Connect:Direct for UNIX Certified Container
- Multiple vulnerabilities in Zimbra Collaboration
- Denial of service in IBM Workload Scheduler
- Denial of service in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in Mitsubishi Electric GT SoftGOT2000
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak System third-party components
- IBM Power System update for OpenSSL
- Multiple vulnerabilities in IBM Virtualization Engine TS7700
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Virtualization 4.9
- Multiple vulnerabilities in OpenShift Virtualization
- Denial of service in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-out 4 (iLO 4)
- Multiple vulnerabilities in Dell DataIQ
- Infinite loop in Dell Avamar Virtual Edition
- Multiple vulnerabilities in Dell VxRail
- Denial of service in Dell EMC OS9
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- Denial of service in Dell EMC Cloud Tiering Appliance
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Denial of service in Dell iDRAC8 and Dell iDRAC9
- Brocade Fabric OS update for OpenSSL
- Multiple vulnerabilities in Hitachi Energy MicroSCADA Pro/X SYS600
- Denial of service in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Denial of service in IBM Sterling Connect:Direct for HP NonStop
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Dell EMCRecoverPoint
- Multiple vulnerabilities in Dell Hybrid Client
- Infinite loop in Dell Client Agent Enabler
- Multiple vulnerabilities in Dell Wyse Management Suite
- Multiple vulnerabilities in Dell EMC NetWorker
- Multiple vulnerabilities in Dell NetWorker Runtime Environment (NRE)
- Multiple vulnerabilities in NETGEAR RAX30
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in Dell Integrated System for Microsoft Azure Stack Hub
- Multiple vulnerabilities in Dell Technologies PowerProtect DD
- Infinite loop in IBM InfoSphere Information Server
- Infinite loop in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products
- Multiple vulnerabilities in Edgecross Basic Software for Windows
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl
- SUSE update for openssl
- SUSE update for openssl-1_0_0
- SUSE update for openssl-1_0_0
- SUSE update for openssl1
- SUSE update for compat-openssl098
- SUSE update for openssl-1_1
- SUSE update for nodejs12
- SUSE update for openssl-1_1
- Infinite loop in IBM Safer Payments
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Infinite loop in IBM Security Verify Bridge Docker image
- Multiple vulnerabilities in Oracle VM Server for x86
- Check Point Gaia update for OpenSSL
- Infinite loop in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in Dell Client Platform
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Infinite loop in Dell PowerVault ME5
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Junos OS update for OpenSSL
- Ubuntu update for nodejs
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Analytics
- openEuler update for intel-sgx-ssl
- openEuler update for linux-sgx
- openEuler update for shim
- openEuler update for mariadb
- openEuler update for openssl
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Security Verify Access
- SolarWinds Platform update for third-party components
- Multiple vulnerabilities in Dell ThinOS
- Gentoo update for Node.js
- Amazon Linux AMI update for mariadb105
- Amazon Linux AMI update for openssl
- openEuler 22.03 LTS SP4 update for edk2
- openEuler 22.03 LTS SP3 update for edk2
- openEuler 20.03 LTS SP4 update for edk2
- openEuler 22.03 LTS SP1 update for edk2
- IBM InfoSphere Master Data Management update for OpenSSL
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Migration Toolkit for Containers 1.7
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in OpenShift Virtualization 4.10
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2
- SUSE update for nodejs14
- SUSE update for nodejs12
- SUSE update for nodejs14
- SUSE update for Security Beta update for SUSE Manager Salt Bundle
- Fedora EPEL 8 update for openssl3
- Fedora 35 update for openssl
- Fedora 34 update for openssl
- Fedora 37 update for openssl1.1
- Fedora 36 update for openssl1.1
- Fedora EPEL 7 update for openssl11
- IBM MobileFirst Foundation update for OpenSSL
- IBM Sterling Connect:Express for UNIX update for OpenSSL
- Anolis OS update for openssl
- Anolis OS update for openssl
- Anolis OS update for compat-openssl10
- Infinite loop in HPE IceWall Products Using OpenSSL
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- IBM DataStage on Cloud Pak for Data update for OpenSSL
- SecurID Authentication Manager update for third-party components
- Arista EOS update for OpenSSL
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM Edge Application Manager
- Infinite loop in Aruba Products
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Business Process Manager (BPM)
- Ubuntu update for edk2
- Ubuntu update for edk2