OS Command Injection in OpenSSL - CVE-2022-1292
Published: May 3, 2022 / Updated: February 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the c_rehash script distributed by some operating systems. A remote attacker with ability to pass data to c_rehash script can and execute arbitrary OS commands with the privileges of the script.
Affected software
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support
SUSE Enterprise Storage
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
IBM AIX
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
VMware Tanzu Application Service for VMs
Isolation Segment
Submariner
Gatekeeper Operator
IBM MQ Operator
IBM Spectrum Copy Data Management
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
EasyApache
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
OpenShift Logging
IBM Sterling Connect:Direct for UNIX
Red Hat Satellite
Tenable Nessus
IBM Rational ClearQuest
Oracle SD-WAN Edge
IBM QRadar WinCollect Agent
IBM Spectrum Protect Plus
Dell EMC Data Protection Search
NetWorker
IBM PureData System for Operational Analytics
Netcool Operations Insight
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Engineering Workflow Management
PowerProtect Data Domain
Steel Belted Radius Carrier Edition
Red Hat OpenStack
PowerProtect Data Manager
IBM Robotic Process Automation
SINAMICS GL150
SINAMICS SL150
SINAMICS PERFECT HARMONY GH180 6SR5
LANTIME Operating System Firmware (LTOS)
RUGGEDCOM ROX MX5000RE
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX MX5000
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1510
SCALANCE S615
Virtualization Engine TS7700 3957-VED
Virtualization Engine TS7700 3957-VEC
PowerScale OneFS
Self Node Remediation Operator
OpenShift sandboxed containers
Multicluster Engine for Kubernetes
OpenShift Service Mesh
Node Maintenance Operator
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Solutions Enabler Virtual Appliance
cflinuxfs3
Tanzu Greenplum for Kubernetes
Telemetry Dashboard
RecoverPoint Classic
Liquidware
Citrix Workspace App
Webex App VDI
Db2 Rest
Storage Defender – Data Protect
ObjectScale
Secured Component Verification (SCV)
Brownfield Connectivity - Client
PowerStore T
EMC ECS
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Solutions Enabler
Unisphere 360
Unisphere for PowerMax
Unisphere for PowerMax Virtual Appliance
eVASA Provider Virtual Appliance
VASA Provider Standalone
Dell Data Protection Central
OpenShift API for Data Protection (OADP)
openssl (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.0.0 (Ubuntu package)
openssl (Ubuntu package)
yggdrasil-worker-forwarder (Red Hat package)
foreman_ygg_worker (Red Hat package)
yggdrasil (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
compat-openssl098-debugsource
libopenssl0_9_8
libopenssl0_9_8-debuginfo
libopenssl0_9_8-32bit
libopenssl0_9_8-debuginfo-32bit
qpid-proton (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-debuginfo
openssl-debugsource
openssl-debuginfo
openssl
libopenssl1_0_0-hmac-32bit
libopenssl1_0_0-hmac
libopenssl1_0_0-debuginfo-32bit
libopenssl1_0_0-32bit
libopenssl1_0_0
libopenssl-devel
openssl-doc
openssl-1_0_0-debugsource
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-doc
openssl-1_0_0-debuginfo
openssl-1_0_0
libopenssl-1_0_0-devel
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-32bit-debuginfo
libopenssl10
libopenssl10-debuginfo
libopenssl1_0_0-steam
libopenssl1_0_0-steam-debuginfo
openssl-1_0_0-cavs
openssl-1_0_0-cavs-debuginfo
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit-debuginfo
libopenssl1_1-32bit
openssl-1_1-debugsource
openssl-1_1-debuginfo
openssl-1_1
libopenssl1_1-hmac
libopenssl1_1-debuginfo
libopenssl1_1
libopenssl-1_1-devel
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-libs
openssl-help
openssl-devel
openssl11
openssl-perl
openssl (Red Hat package)
openssl1.1
dev-libs/openssl
libssl1.1 (Ubuntu package)
rubygem-foreman_maintain (Red Hat package)
jws5-tomcat-native (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-safemode (Red Hat package)
rubygem-safemode (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
tfm-rubygem-rchardet (Red Hat package)
rubygem-rchardet (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
tfm-rubygem-git (Red Hat package)
rubygem-git (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
intel-sgx-ssl-devel
intel-sgx-ssl
sgx-dcap-pccs
sgx-ra-service
libsgx-aesm-ecdsa-plugin
linux-sgx
libsgx-dcap-ql
libsgx-launch-devel
sgx-aesm-service
libsgx-uae-service
libsgx-aesm-launch-plugin
libsgx-enclave-common-devel
libsgx-qe3-logic
linux-sgx-debuginfo
libsgx-ae-qve
linux-sgx-debugsource
libsgx-dcap-ql-devel
libsgx-dcap-quote-verify-devel
libsgx-ra-uefi
sgx-pck-id-retrieval-tool
libsgx-epid
libsgx-quote-ex
libsgx-ae-le
libsgx-aesm-pce-plugin
libsgx-ae-qe3
libsgx-dcap-default-qpl-devel
libsgx-dcap-default-qpl
libsgx-pce-logic
libsgx-ae-pce
libsgx-ra-uefi-devel
libsgx-aesm-epid-plugin
libsgx-ra-network-devel
libsgx-dcap-quote-verify
libsgx-launch
libsgx-quote-ex-devel
libsgx-enclave-common
libsgx-aesm-quote-ex-plugin
libsgx-epid-devel
libsgx-ra-network
sgxsdk
libsgx-ae-epid
libsgx-urts
openssl3
libopenssl-3-devel
openssl-3-doc
openssl-3-debuginfo
openssl-3
libopenssl3
libopenssl3-debuginfo
libopenssl-3-devel-32bit
libopenssl3-32bit
openssl-3-debugsource
libopenssl3-32bit-debuginfo
libssl3 (Ubuntu package)
foreman (Red Hat package)
python-gitpython (Red Hat package)
python-django (Red Hat package)
foreman-installer (Red Hat package)
python-pulpcore (Red Hat package)
rubygem-katello (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
puppet-agent (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
nodejs-doc (Ubuntu package)
nodejs (Ubuntu package)
libnode72 (Ubuntu package)
libnode-dev (Ubuntu package)
Migration Toolkit for Containers
Nessus Network Monitor
Red Hat OpenShift Container Platform
Traffix SDC
JD Edwards EnterpriseOne Tools
VMware Horizon Client
GT SoftGOT2000
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
JBoss Core Services
IBM VIOS
EMC Integrated Data Protection Appliance
Dell EMC NetWorker vProxy
JBoss Web Server
Red Hat Ceph Storage
MySQL Server
IBM InfoSphere Information Server
MySQL Workbench
Engineering Lifecycle Management
IBM Security Verify Access
Oracle Enterprise Manager Ops Center
Cisco Jabber
Sophos Firewall
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Cisco Webex Meetings
Cloud Pak for Security (CP4S)
Integrated Data protection Appliance (IDPA)
Data Protection Search
NetWorker Management Console
IBM Cloud Pak System
SCALANCE M874-2
SCALANCE M876-3 (EVDO)
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE S615 EEC
SCALANCE M874-3
SCALANCE M826-2 SHDSL-Router
SCALANCE M816-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M804PB
RUGGEDCOM RM1224 LTE(4G) NAM
RUGGEDCOM RM1224 LTE(4G) EU
Dell EMC VxRail Appliance
Gaia
How to mitigate CVE-2022-1292
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
Self Node Remediation Operator - update to 0.4.1
cflinuxfs3 - update to 0.292.0
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
OpenShift sandboxed containers - update to 1.3.1
Tanzu Greenplum for Kubernetes - update to 2.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Debian package) - addressed in versions 1.1.1n-0+deb10u2, 1.1.1n-0+deb11u2
IBM MQ Operator - addressed in versions 1.3.7, 2.0.2
Migration Toolkit for Containers - update to 1.7.4
GT SoftGOT2000 - update to 1.280S
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1
IBM Spectrum Copy Data Management - update to 2.2.17
OpenShift Service Mesh - update to 2.2.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.2, 2.6.0
JBoss Core Services - update to 2.4.51 SP1
Nessus Network Monitor - update to 6.1.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
EasyApache - update to 4 2022-5-11
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.1
Node Maintenance Operator - update to 4.11.1
JBoss Web Server - update to 5.7.1
RecoverPoint Classic - update to 5.1 SP4 P4
OpenShift Logging - addressed in versions 5.3.11, 5.3.14, 5.4.5, 5.5.5
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Red Hat Satellite - addressed in versions 6.11.5.6, 6.12.5.2, 6.13.5, 6.14
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.032, 7.04.017
Tenable Nessus - update to 8.15.9
IBM Rational ClearQuest - addressed in versions 9.0.1.14, 9.0.2.6, 9.1.0.3
JD Edwards EnterpriseOne Tools - update to 9.2.6.4
IBM QRadar WinCollect Agent - update to 10.0.2
IBM Security Verify Access - update to 10.0.5.0
IBM Spectrum Protect Plus - update to 10.1.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Sophos Firewall - addressed in versions 18.5.4, 19.0.1
Dell EMC Data Protection Search - update to 19.6.2
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2g1ubuntu4.20+esm3, 1.0.2n-1ubuntu5.9
openssl (Ubuntu package) - update to Ubuntu Pro
yggdrasil-worker-forwarder (Red Hat package) - addressed in versions 0.0.3-1.el7sat, 0.0.3-1.el8sat
foreman_ygg_worker (Red Hat package) - addressed in versions 0.2.2-1.el7sat, 0.2.2-1.el8sat, 0.2.2-1.el9sat
yggdrasil (Red Hat package) - addressed in versions 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-32.el7jbcs, 0.4.10-32.el8jbcs
compat-openssl098-debugsource - update to 0.9.8j-106.36.1
libopenssl0_9_8 - update to 0.9.8j-106.36.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.36.1
libopenssl0_9_8-32bit - update to 0.9.8j-106.36.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.36.1
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8, 0.37.0-2.el9
SINEC INS - update to 1.0 SP2 Update 1
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-17.el7jbcs, 1.0.0-17.el8jbcs
Db2 Rest - update to 1.0.0.304
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
openssl-debugsource - update to 1.0.2j-60.80.1
openssl-debuginfo - update to 1.0.2j-60.80.1
openssl - update to 1.0.2j-60.80.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1
libopenssl1_0_0-32bit - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0 - addressed in versions 1.0.2j-60.80.1, 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl-devel - update to 1.0.2j-60.80.1
openssl-doc - update to 1.0.2j-60.80.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.53.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl10 - update to 1.0.2p-150000.3.56.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.56.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.56.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1 - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1 - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150000.4.69.1, 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.30.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
IBM PureData System for Operational Analytics - update to 1.1 FP5
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.66.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-libs - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl-help - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl-debuginfo - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl-debugsource - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl-devel - addressed in versions 1.1.1f-16, 1.1.1f-17
openssl11 - update to 1.1.1k-4.el7
openssl-perl - update to 1.1.1k-7.0.1
openssl-libs - update to 1.1.1k-7.0.1
openssl-devel - update to 1.1.1k-7.0.1
openssl - update to 1.1.1k-7.0.1
openssl (Red Hat package) - addressed in versions 1.1.1k-7.el8_6, 3.0.1-41.el9_0
openssl - update to 1.1.1o-1.fc35
openssl1.1 - addressed in versions 1.1.1o-1.fc36, 1.1.1o-1.fc37
dev-libs/openssl - update to 1.1.1q
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.3, 1.1.1f-1ubuntu2.13, 1.1.1-1ubuntu2.1~18.04.17
rubygem-foreman_maintain (Red Hat package) - update to 1.2.12-1.el8sat
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-11.redhat_11.el7jws, 1.2.31-11.redhat_11.el8jws, 1.2.31-11.redhat_11.el9jws
pulpcore-selinux (Red Hat package) - update to 1.3.3-1.el8pc
tfm-rubygem-safemode (Red Hat package) - update to 1.3.8-0.1.el7sat
rubygem-safemode (Red Hat package) - addressed in versions 1.3.8-0.1.el8sat, 1.3.8-1.el8sat
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-13.el7jbcs, 1.3.17-13.el8jbcs
Storage Defender – Data Protect - update to 1.4.0
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-99.el7jbcs, 1.6.1-99.el8jbcs
Netcool Operations Insight - update to 1.6.8
tfm-rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el7sat
rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el8sat
Cloud Pak for Security (CP4S) - update to 1.10.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-20.el7jbcs, 1.15.19-20.el8jbcs
tfm-rubygem-git (Red Hat package) - update to 1.18.0-0.1.el7sat
rubygem-git (Red Hat package) - addressed in versions 1.18.0-0.1.el8sat, 1.18.0-1.el8sat
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-11.el7jbcs, 1.43.0-11.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
IBM Cloud Pak System - update to 2.3.4.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-37.el7jbcs, 2.4.51-37.el8jbcs
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-22.el7jbcs, 2.9.3-22.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
intel-sgx-ssl-devel - update to 2.10-4
intel-sgx-ssl - update to 2.10-4
sgx-dcap-pccs - addressed in versions 2.11.100-11, 2.11.100-12
sgx-ra-service - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-aesm-ecdsa-plugin - addressed in versions 2.11.100-11, 2.11.100-12
linux-sgx - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-ql - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-launch-devel - addressed in versions 2.11.100-11, 2.11.100-12
sgx-aesm-service - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-uae-service - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-aesm-launch-plugin - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-enclave-common-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-qe3-logic - addressed in versions 2.11.100-11, 2.11.100-12
linux-sgx-debuginfo - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ae-qve - addressed in versions 2.11.100-11, 2.11.100-12
linux-sgx-debugsource - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-ql-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-quote-verify-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ra-uefi - addressed in versions 2.11.100-11, 2.11.100-12
sgx-pck-id-retrieval-tool - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-epid - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-quote-ex - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ae-le - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-aesm-pce-plugin - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ae-qe3 - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-default-qpl-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-default-qpl - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-pce-logic - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ae-pce - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ra-uefi-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-aesm-epid-plugin - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ra-network-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-dcap-quote-verify - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-launch - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-quote-ex-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-enclave-common - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-aesm-quote-ex-plugin - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-epid-devel - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ra-network - addressed in versions 2.11.100-11, 2.11.100-12
sgxsdk - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-ae-epid - addressed in versions 2.11.100-11, 2.11.100-12
libsgx-urts - addressed in versions 2.11.100-11, 2.11.100-12
Brownfield Connectivity - Client - update to 2.15
RUGGEDCOM ROX MX5000RE - update to 2.16.0
RUGGEDCOM ROX RX5000 - update to 2.16.0
RUGGEDCOM ROX RX1536 - update to 2.16.0
RUGGEDCOM ROX RX1524 - update to 2.16.0
RUGGEDCOM ROX RX1512 - update to 2.16.0
RUGGEDCOM ROX RX1400 - update to 2.16.0
RUGGEDCOM ROX RX1500 - update to 2.16.0
RUGGEDCOM ROX RX1511 - update to 2.16.0
RUGGEDCOM ROX MX5000 - update to 2.16.0
RUGGEDCOM ROX RX1501 - update to 2.16.0
RUGGEDCOM ROX RX1510 - update to 2.16.0
openssl3 - update to 3.0.1-41.el8.1
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.1
openssl - update to 3.0.5-1
foreman (Red Hat package) - addressed in versions 3.1.1.27-1.el7sat, 3.1.1.27-1.el8sat, 3.3.0.23-1.el8sat, 3.5.1.23-1.el8sat
python-gitpython (Red Hat package) - update to 3.1.32-1.el8pc
python-django (Red Hat package) - update to 3.2.21-1.el8pc
PowerStore T - update to 3.5.0.1-2083289
foreman-installer (Red Hat package) - update to 3.5.2.4-1.el8sat
EMC ECS - update to 3.7.0.3
IBM Cloud Transformation Advisor - update to 3.10.0
python-pulpcore (Red Hat package) - update to 3.21.18-1.el8pc
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Dell EMC NetWorker vProxy - update to 4.3.0-32
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
rubygem-katello (Red Hat package) - update to 4.7.0.33-1.el8sat
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
Dell Secure Connect Gateway - update to 5.28.00.14
satellite (Red Hat package) - addressed in versions 6.11.5.6-1.el7sat, 6.11.5.6-1.el8sat, 6.12.5.2-1.el8sat, 6.13.5-1.el8sat
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
rubygem-foreman_rh_cloud (Red Hat package) - update to 7.0.48-1.el8sat
SCALANCE M874-2 - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE S615 - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M804PB - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
puppet-agent (Red Hat package) - addressed in versions 7.26.0-3.el6sat, 7.26.0-3.el7sat, 7.26.0-3.el8sat, 7.26.0-3.el9sat
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.86.0-2.el7jbcs, 7.86.0-2.el8jbcs
Dell EMC VxRail Appliance - update to 8.0.000
Steel Belted Radius Carrier Edition - update to 8.6.0R16
Virtualization Engine TS7700 3957-VED - addressed in versions 8.50.2.6 VTD_EXEC.279, 8.51.2.12 VTD_EXEC.279, 8.52.101.12 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.50.2.6 VTD_EXEC.279, 8.51.2.12 VTD_EXEC.279, 8.52.101.12 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279
Solutions Enabler Virtual Appliance - update to 9.2.3.5
Solutions Enabler - update to 9.2.3.5
Unisphere 360 - update to 9.2.3.8
Unisphere for PowerMax - update to 9.2.3.20
Unisphere for PowerMax Virtual Appliance - update to 9.2.3.20
eVASA Provider Virtual Appliance - update to 9.2.4.11
VASA Provider Standalone - update to 9.2.4.21
PowerScale OneFS - update to 9.5.0.6
rubygem-foreman_theme_satellite (Red Hat package) - update to 11.0.0.6-1.el8sat
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4
nodejs-doc (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode-dev (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
Red Hat OpenStack - update to 16.2.z
Data Protection Search - update to 19.6.6
Dell Data Protection Central - update to 19.7.0-9
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
PowerProtect Data Manager - update to 19.19.0-15
IBM Robotic Process Automation - update to 21.0.5
Gaia - update to R81.10 Take 95
Links to Public Exploits and PoC-codes
External References
- https://www.openssl.org/news/secadv/20220503.txt
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=548d3f280a6e737673f5b61fce24bb100108dfeb
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Slackware Linux update for openssl
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Multiple vulnerabilities in cPanel EasyApache
- Debian update for openssl
- Ubuntu update for openssl
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl
- SUSE update for openssl-1_0_0
- Slackware Linux update for openssl
- SUSE update for openssl-1_1
- Slackware Linux update for Slackware 14.2 openssl
- SUSE update for openssl-1_0_0
- SUSE update for openssl-1_1
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- SUSE update for openssl-3
- SUSE update for openssl-1_1
- SUSE update for openssl-1_0_0
- Multiple vulnerabilities in Oracle Enterprise Manager Ops Center
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in IBM Rational ClearQuest
- VMware Tanzu products update for OpenSSL
- Red Hat Enterprise Linux 8 update for openssl
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in Mitsubishi Electric GT SoftGOT2000
- Multiple vulnerabilities in Red Hat Ceph Storage 5.2
- Traffix SDC update for OpenSSL
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Multiple vulnerabilities in Logging Subsystem for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in IBM Virtualization Engine TS7700
- Red Hat Enterprise Linux 9 update for openssl
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator
- Multiple vulnerabilities in Red Hat Node Maintenance Operator
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in Red Hat Gatekeeper Operator
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.4
- Multiple vulnerabilities in Submariner
- Multiple vulnerabilities in Multicluster Engine for Kubernetes
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management
- Multiple vulnerabilities in Multicluster Engine for Kubernetes
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.0
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.5
- Multiple vulnerabilities in Red Hat OpenStack Platform 16.2
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- OS Command Injection in IBM Sterling Connect:Direct for UNIX Container
- Multuiple vulnerabilities in Sophos Firewall
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Dell products
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT)
- Multiple vulnerabilities in OpenShift sandboxed containers
- Oracle Solaris update for third-party software
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Red Hat JBoss Core Services update for Apache HTTP Server
- Multiple vulnerabilities in Openshift Logging 5.3
- Multiple vulnerabilities in JBoss Enterprise Web Server
- Multiple vulnerabilities in OpenShift Logging 5.5
- Multiple vulnerabilities in Dell Technologies PowerProtect DD
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilites in Siemens Brownfield Connectivity - Client
- Multiple vulnerabilities in Tenable Nessus
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Oracle SD-WAN Edge
- OS Command Injection in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in Dell RecoverPoint Classic
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- Check Point Gaia update for OpenSSL
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Multiple vulnerabilities in Siemens RUGGEDCOM ROX devices
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Red Hat Satellite
- Multiple vulnerabilities in Red Hat Satellite 6.11
- Multiple vulnerabilities in Red Hat Satellite 6.12
- Multiple vulnerabilities in Red Hat Satellite Client
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Ubuntu update for nodejs
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in Red Hat Satellite 6.14
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for intel-sgx-ssl
- openEuler update for linux-sgx
- openEuler update for linux-sgx
- openEuler update for openssl
- openEuler update for openssl
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Cloud Pak System
- Ubuntu update for openssl
- Fedora 37 update for openssl1.1
- Fedora 36 update for openssl1.1
- Fedora 35 update for openssl
- Fedora EPEL 7 update for openssl11
- Fedora EPEL 8 update for openssl3
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Anolis OS update for openssl
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Meinberg LANTIME firmware update for OpenSSL
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell NetWorker and NetWorker Management Console
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in F5 Traffix SDC OpenSSL component
- Dell NetWorker update for OpenSSL