OS Command Injection in OpenSSL - CVE-2022-2068

 

OS Command Injection in OpenSSL - CVE-2022-2068

Published: June 21, 2022 / Updated: October 5, 2022


Vulnerability identifier: #VU64559
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2068
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the c_rehash script distributed by some operating systems. A remote attacker with ability to pass data to c_rehash script can and execute arbitrary OS commands with the privileges of the script.

The vulnerability exists due to incomplete fix for #VU62765 (CVE-2022-1292).


Affected software

OpenSSL
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
IBM AIX
SUSE Linux Enterprise Storage
IBM i
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Security Directory Integrator
Telemetry Dashboard
RecoverPoint Classic
Liquidware
IBM Virtualization Engine TS7700 3948-VED
Citrix Workspace App
Webex App VDI
Db2 Rest
ObjectScale
IBM Aspera Shares
Secured Component Verification (SCV)
PowerStore T
EMC ECS
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
eVASA Provider Virtual Appliance
VASA Provider Standalone
IBM Security Verify Directory
Dell Data Protection Central
GT SoftGOT2000
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
Submariner
Gatekeeper Operator
IBM MQ Operator
IBM Spectrum Copy Data Management
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
EasyApache
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
OpenShift Logging
IBM Spectrum Control
IBM Sterling Connect:Direct for UNIX
Red Hat Satellite
IBM Rational Build Forge
Tenable Nessus
Oracle SD-WAN Edge
IBM Spectrum Protect Plus
Dell EMC Data Protection Search
NetWorker
Netcool Operations Insight
IBM SANnav Management Portal
Red Hat OpenShift distributed tracing (RHOSDT)
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
IBM Aspera Orchestrator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
PowerProtect Data Domain
IBM Rational ClearCase
IBM Rational ClearQuest
Red Hat OpenStack
PowerProtect Data Manager
IBM Robotic Process Automation
Self Node Remediation Operator
OpenShift sandboxed containers
Multicluster Engine for Kubernetes
OpenShift Service Mesh
Node Maintenance Operator
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Solutions Enabler Virtual Appliance
OpenShift API for Data Protection (OADP)
openssl (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.0.0 (Ubuntu package)
openssl (Ubuntu package)
yggdrasil-worker-forwarder (Red Hat package)
foreman_ygg_worker (Red Hat package)
yggdrasil (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8-debuginfo-32bit
libopenssl0_9_8-32bit
libopenssl0_9_8-debuginfo
libopenssl0_9_8
compat-openssl098-debugsource
qpid-proton (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-hmac-32bit
openssl-doc
libopenssl-devel
libopenssl1_0_0
libopenssl1_0_0-32bit
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
libopenssl1_0_0-hmac
openssl
openssl-debuginfo
openssl-debugsource
openssl-1_0_0-debuginfo
openssl-1_0_0-doc
libopenssl-1_0_0-devel
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-debugsource
openssl-1_0_0
openssl1.0 (Ubuntu package)
openssl-1_0_0-cavs-debuginfo
openssl-1_0_0-cavs
libopenssl1_0_0-steam-debuginfo
libopenssl1_0_0-steam
libopenssl10
libopenssl10-debuginfo
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-32bit-debuginfo
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel
libopenssl1_1
libopenssl1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
openssl-1_1-debuginfo
openssl-1_1-debugsource
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-libs
openssl-devel
openssl-help
openssl11
openssl-perl
openssl (Red Hat package)
openssl1.1
rubygem-foreman_maintain (Red Hat package)
jws5-tomcat-native (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-safemode (Red Hat package)
rubygem-safemode (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
tfm-rubygem-rchardet (Red Hat package)
rubygem-rchardet (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
tfm-rubygem-git (Red Hat package)
rubygem-git (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
intel-sgx-ssl
intel-sgx-ssl-devel
libsgx-ra-uefi
libsgx-dcap-ql-devel
libsgx-dcap-quote-verify-devel
libsgx-ae-pce
sgx-pck-id-retrieval-tool
libsgx-epid
libsgx-aesm-pce-plugin
libsgx-ae-qe3
libsgx-dcap-default-qpl
libsgx-aesm-ecdsa-plugin
libsgx-pce-logic
libsgx-launch-devel
libsgx-ra-network
sgx-aesm-service
libsgx-dcap-ql
linux-sgx
libsgx-ra-uefi-devel
libsgx-aesm-launch-plugin
libsgx-dcap-default-qpl-devel
libsgx-enclave-common-devel
libsgx-ae-le
libsgx-qe3-logic
libsgx-ae-qve
sgxsdk
libsgx-quote-ex
libsgx-uae-service
linux-sgx-debugsource
sgx-dcap-pccs
sgx-ra-service
libsgx-epid-devel
libsgx-aesm-quote-ex-plugin
libsgx-enclave-common
libsgx-launch
libsgx-ra-network-devel
libsgx-dcap-quote-verify
libsgx-quote-ex-devel
libsgx-ae-epid
libsgx-urts
libsgx-aesm-epid-plugin
linux-sgx-debuginfo
openssl3
libopenssl-3-devel
openssl-3-debuginfo
libopenssl3-32bit-debuginfo
libopenssl3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
openssl-3-doc
openssl-3-debugsource
openssl-3
foreman (Red Hat package)
python-gitpython (Red Hat package)
python-django (Red Hat package)
foreman-installer (Red Hat package)
python-pulpcore (Red Hat package)
rubygem-katello (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
puppet-agent (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
libnode-dev (Ubuntu package)
libnode72 (Ubuntu package)
nodejs (Ubuntu package)
nodejs-doc (Ubuntu package)
Migration Toolkit for Containers
Nessus Network Monitor
Red Hat OpenShift Container Platform
Traffix SDC
IBM App Connect Professional
VMware Horizon Client
JBoss Core Services
IBM VIOS
EMC Integrated Data Protection Appliance
Splunk Enterprise
Dell EMC NetWorker vProxy
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
IBM Integrated Analytics System
JBoss Web Server
Red Hat Ceph Storage
Splunk Universal Forwarder
Zimbra Collaboration
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
RUGGEDCOM ROX MX5000RE
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX MX5000
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1510
FOS Firmware
PowerScale OneFS
IBM Security Verify Access
Cisco Jabber
Cisco Webex Meetings
Communications Unified Assurance
Cloud Pak for Security (CP4S)
Integrated Data protection Appliance (IDPA)
Data Protection Search
NetWorker Management Console
Dell EMC VxRail Appliance
Gaia
IBM InfoSphere Information Server

How to mitigate CVE-2022-2068

Install updates from vendor's website.

OpenSSL - addressed in versions 1.0.2zf, 1.1.1p, 3.0.4
GT SoftGOT2000 - update to 1.285X
Submariner - update to 0.13.0
Gatekeeper Operator - update to 0.2
Self Node Remediation Operator - update to 0.4.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
OpenShift sandboxed containers - update to 1.3.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
openssl (Debian package) - addressed in versions 1.1.1n-0+deb10u3, 1.1.1n-0+deb11u3
IBM MQ Operator - addressed in versions 1.3.7, 2.0.2
Migration Toolkit for Containers - update to 1.7.4
Multicluster Engine for Kubernetes - addressed in versions 2.0.2, 2.1
OpenShift Service Mesh - update to 2.2.2
IBM Spectrum Copy Data Management - update to 2.2.17
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.12, 2.4.6, 2.5.2, 2.6.0
JBoss Core Services - update to 2.4.51 SP1
Nessus Network Monitor - update to 6.1.0
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
EasyApache - update to 4 2022-6-22
IBM Aspera Faspex for Windows - update to 4.4.2 PL2
IBM Aspera Faspex for Linux - update to 4.4.2 PL2
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.1
Node Maintenance Operator - update to 4.11.1
JBoss Web Server - update to 5.7.1
RecoverPoint Classic - update to 5.1 SP4 P4
OpenShift Logging - addressed in versions 5.3.11, 5.3.14, 5.4.5, 5.5.5
IBM Spectrum Control - update to 5.4.8
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Red Hat Satellite - addressed in versions 6.11.5.6, 6.12.5.2, 6.13.5, 6.14
IBM Rational Build Forge - update to 8.0.0.24
IBM App Connect Professional - update to 7.5.5.0
Tenable Nessus - update to 8.15.9
Splunk Enterprise - addressed in versions 8.1.11, 8.2.7.1, 9.0.1
Zimbra Collaboration - addressed in versions 8.8.15 Patch 33, 9.0.0 Patch 26
Virtualization Engine TS7700 3957-VEC - addressed in versions 8.51.2.12 VTD_EXEC.279, 8.52.102.13 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279, 8.53.0.63 VTD_EXEC.279
Virtualization Engine TS7700 3957-VED - addressed in versions 8.51.2.12 VTD_EXEC.279, 8.52.102.13 VTD_EXEC.279, 8.52.200.111 VTD_EXEC.279, 8.53.0.63 VTD_EXEC.279
IBM Virtualization Engine TS7700 3948-VED - update to 8.53.0.63 VTD_EXEC.279
IBM Security Verify Access - update to 10.0.5.0
IBM Spectrum Protect Plus - update to 10.1.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Dell EMC Data Protection Search - update to 19.6.2
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - update to Ubuntu Pro
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2g1ubuntu4.20+esm5, 1.1.1l-1ubuntu1.5, 1.1.1f-1ubuntu2.15, 1.1.1-1ubuntu2.1~18.04.19, 3.0.2-0ubuntu1.5
yggdrasil-worker-forwarder (Red Hat package) - addressed in versions 0.0.3-1.el7sat, 0.0.3-1.el8sat
foreman_ygg_worker (Red Hat package) - addressed in versions 0.2.2-1.el7sat, 0.2.2-1.el8sat, 0.2.2-1.el9sat
yggdrasil (Red Hat package) - addressed in versions 0.2.3-1.el7sat, 0.2.3-1.el8sat, 0.2.3-1.el9sat
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-32.el7jbcs, 0.4.10-32.el8jbcs
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.36.1
libopenssl0_9_8-32bit - update to 0.9.8j-106.36.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.36.1
libopenssl0_9_8 - update to 0.9.8j-106.36.1
compat-openssl098-debugsource - update to 0.9.8j-106.36.1
qpid-proton (Red Hat package) - addressed in versions 0.37.0-2.el8, 0.37.0-2.el9
SINEC INS - update to 1.0 SP2 Update 1
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-17.el7jbcs, 1.0.0-17.el8jbcs
Db2 Rest - update to 1.0.0.304
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl-doc - update to 1.0.2j-60.83.1
libopenssl-devel - update to 1.0.2j-60.83.1
libopenssl1_0_0 - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-32bit - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.83.1, 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl - update to 1.0.2j-60.83.1
openssl-debuginfo - update to 1.0.2j-60.83.1
openssl-debugsource - update to 1.0.2j-60.83.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.56.1, 1.0.2p-150000.3.56.1
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.10
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.56.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.56.1
libopenssl10 - update to 1.0.2p-150000.3.56.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.56.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.56.1
IBM Integrated Analytics System - update to 1.0.30.0
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1 - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1 - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150000.4.74.1, 1.1.0i-150100.14.33.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.33.1, 1.1.1d-2.66.1, 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.66.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.48.1, 1.1.1l-150400.7.7.1
openssl-debugsource - update to 1.1.1f-17
openssl - update to 1.1.1f-17
openssl-libs - update to 1.1.1f-17
openssl-debuginfo - update to 1.1.1f-17
openssl-devel - update to 1.1.1f-17
openssl-help - update to 1.1.1f-17
openssl11 - update to 1.1.1k-4.el7
openssl-devel - update to 1.1.1k-7.0.1
openssl-perl - update to 1.1.1k-7.0.1
openssl-libs - update to 1.1.1k-7.0.1
openssl - update to 1.1.1k-7.0.1
openssl (Red Hat package) - addressed in versions 1.1.1k-7.el8_6, 3.0.1-41.el9_0
openssl - addressed in versions 1.1.1q-1.fc35, 1.1.1p-1.fc35, 3.0.5-1.fc37
openssl1.1 - addressed in versions 1.1.1p-1.fc36, 1.1.1p-1.fc37
rubygem-foreman_maintain (Red Hat package) - update to 1.2.12-1.el8sat
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-11.redhat_11.el7jws, 1.2.31-11.redhat_11.el8jws, 1.2.31-11.redhat_11.el9jws
pulpcore-selinux (Red Hat package) - update to 1.3.3-1.el8pc
tfm-rubygem-safemode (Red Hat package) - update to 1.3.8-0.1.el7sat
rubygem-safemode (Red Hat package) - addressed in versions 1.3.8-0.1.el8sat, 1.3.8-1.el8sat
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-13.el7jbcs, 1.3.17-13.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-99.el7jbcs, 1.6.1-99.el8jbcs
Netcool Operations Insight - update to 1.6.8
tfm-rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el7sat
rubygem-rchardet (Red Hat package) - update to 1.8.0-0.1.el8sat
IBM Aspera Shares - update to 1.10.0 PL4
Cloud Pak for Security (CP4S) - update to 1.10.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-20.el7jbcs, 1.15.19-20.el8jbcs
tfm-rubygem-git (Red Hat package) - update to 1.18.0-0.1.el7sat
rubygem-git (Red Hat package) - addressed in versions 1.18.0-0.1.el8sat, 1.18.0-1.el8sat
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-11.el7jbcs, 1.43.0-11.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
IBM SANnav Management Portal - update to 2.3.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-37.el7jbcs, 2.4.51-37.el8jbcs
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
Isolation Segment - addressed in versions 2.7.47, 2.10.27, 2.11.16, 2.12.11
VMware Tanzu Application Service for VMs - addressed in versions 2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-22.el7jbcs, 2.9.3-22.el8jbcs
intel-sgx-ssl - update to 2.10-4
intel-sgx-ssl-devel - update to 2.10-4
libsgx-ra-uefi - update to 2.11.100-11
libsgx-dcap-ql-devel - update to 2.11.100-11
libsgx-dcap-quote-verify-devel - update to 2.11.100-11
libsgx-ae-pce - update to 2.11.100-11
sgx-pck-id-retrieval-tool - update to 2.11.100-11
libsgx-epid - update to 2.11.100-11
libsgx-aesm-pce-plugin - update to 2.11.100-11
libsgx-ae-qe3 - update to 2.11.100-11
libsgx-dcap-default-qpl - update to 2.11.100-11
libsgx-aesm-ecdsa-plugin - update to 2.11.100-11
libsgx-pce-logic - update to 2.11.100-11
libsgx-launch-devel - update to 2.11.100-11
libsgx-ra-network - update to 2.11.100-11
sgx-aesm-service - update to 2.11.100-11
libsgx-dcap-ql - update to 2.11.100-11
linux-sgx - update to 2.11.100-11
libsgx-ra-uefi-devel - update to 2.11.100-11
libsgx-aesm-launch-plugin - update to 2.11.100-11
libsgx-dcap-default-qpl-devel - update to 2.11.100-11
libsgx-enclave-common-devel - update to 2.11.100-11
libsgx-ae-le - update to 2.11.100-11
libsgx-qe3-logic - update to 2.11.100-11
libsgx-ae-qve - update to 2.11.100-11
sgxsdk - update to 2.11.100-11
libsgx-quote-ex - update to 2.11.100-11
libsgx-uae-service - update to 2.11.100-11
linux-sgx-debugsource - update to 2.11.100-11
sgx-dcap-pccs - update to 2.11.100-11
sgx-ra-service - update to 2.11.100-11
libsgx-epid-devel - update to 2.11.100-11
libsgx-aesm-quote-ex-plugin - update to 2.11.100-11
libsgx-enclave-common - update to 2.11.100-11
libsgx-launch - update to 2.11.100-11
libsgx-ra-network-devel - update to 2.11.100-11
libsgx-dcap-quote-verify - update to 2.11.100-11
libsgx-quote-ex-devel - update to 2.11.100-11
libsgx-ae-epid - update to 2.11.100-11
libsgx-urts - update to 2.11.100-11
libsgx-aesm-epid-plugin - update to 2.11.100-11
linux-sgx-debuginfo - update to 2.11.100-11
RUGGEDCOM ROX MX5000RE - update to 2.16.0
RUGGEDCOM ROX RX1400 - update to 2.16.0
RUGGEDCOM ROX MX5000 - update to 2.16.0
RUGGEDCOM ROX RX1501 - update to 2.16.0
RUGGEDCOM ROX RX1500 - update to 2.16.0
RUGGEDCOM ROX RX5000 - update to 2.16.0
RUGGEDCOM ROX RX1536 - update to 2.16.0
RUGGEDCOM ROX RX1524 - update to 2.16.0
RUGGEDCOM ROX RX1512 - update to 2.16.0
RUGGEDCOM ROX RX1511 - update to 2.16.0
RUGGEDCOM ROX RX1510 - update to 2.16.0
openssl3 - update to 3.0.1-41.el8.1
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
openssl - update to 3.0.5-1
foreman (Red Hat package) - addressed in versions 3.1.1.27-1.el7sat, 3.1.1.27-1.el8sat, 3.3.0.23-1.el8sat, 3.5.1.23-1.el8sat
python-gitpython (Red Hat package) - update to 3.1.32-1.el8pc
python-django (Red Hat package) - update to 3.2.21-1.el8pc
PowerStore T - update to 3.5.0.1-2083289
foreman-installer (Red Hat package) - update to 3.5.2.4-1.el8sat
EMC ECS - update to 3.7.0.3
IBM Cloud Transformation Advisor - update to 3.10.0
python-pulpcore (Red Hat package) - update to 3.21.18-1.el8pc
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Dell EMC NetWorker vProxy - update to 4.3.0-32
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
rubygem-katello (Red Hat package) - update to 4.7.0.33-1.el8sat
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
OpenShift Virtualization - addressed in versions 4.11.0, 4.11.1, 4.12.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Communications Unified Assurance - update to 5.5.7
Dell Secure Connect Gateway - update to 5.28.00.14
satellite (Red Hat package) - addressed in versions 6.11.5.6-1.el7sat, 6.11.5.6-1.el8sat, 6.12.5.2-1.el8sat, 6.13.5-1.el8sat
rubygem-foreman_rh_cloud (Red Hat package) - update to 7.0.48-1.el8sat
PowerProtect Data Domain - addressed in versions 7.7.4, 7.10.0.0
puppet-agent (Red Hat package) - addressed in versions 7.26.0-3.el6sat, 7.26.0-3.el7sat, 7.26.0-3.el8sat, 7.26.0-3.el9sat
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.86.0-2.el7jbcs, 7.86.0-2.el8jbcs
Dell EMC VxRail Appliance - update to 8.0.000
Splunk Universal Forwarder - addressed in versions 8.1.11, 8.2.7.1, 9.0.1
IBM Rational ClearCase - addressed in versions 9.0.2.7, 9.1.0.4, 10.0.0.1
IBM Rational ClearQuest - addressed in versions 9.0.2.7, 9.1.0.4
FOS Firmware - update to 9.2.0a
Solutions Enabler Virtual Appliance - update to 9.2.3.5
Solutions Enabler - update to 9.2.3.5
Unisphere 360 - update to 9.2.3.8
Unisphere for PowerMax Virtual Appliance - update to 9.2.3.20
Unisphere for PowerMax - update to 9.2.3.20
eVASA Provider Virtual Appliance - update to 9.2.4.11
VASA Provider Standalone - update to 9.2.4.21
PowerScale OneFS - update to 9.5.0.6
IBM Security Verify Directory - update to 10.0.3.1
rubygem-foreman_theme_satellite (Red Hat package) - update to 11.0.0.6-1.el8sat
IBM InfoSphere Information Server - addressed in versions 11.7.1.0, 11.7.1.4
libnode-dev (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
nodejs-doc (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.1
Red Hat OpenStack - update to 16.2.z
Data Protection Search - update to 19.6.6
Dell Data Protection Central - update to 19.7.0-9
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
PowerProtect Data Manager - update to 19.19.0-15
IBM Robotic Process Automation - update to 21.0.5
Gaia - update to R81.10 Take 95

External References

Related Security Bulletins