Double Free in OpenSSL - CVE-2022-4450
Published: February 7, 2023 / Updated: January 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the PEM_read_bio_ex() function. A remote attacker can pass specially crafted PEM file to the application, trigger a double free error and perform a denial of service (DoS) attack.
Affected software
AFS650
SCALANCE W1750D (ROW)
SCALANCE W1750D (USA)
AFS660-C
AFS665-B
AFS670-V2
AFS670
AFS675
AFS677
AFR677
PCULogger tool
SCALANCE W1750D (JP)
QuTS hero
Fujitsu M12-1
Fujitsu M12-2
Fujitsu M12-2S
LANTIME Operating System Firmware (LTOS)
IBM Power System AC922
PowerEdge R660
PowerEdge R760
PowerEdge C6620
PowerEdge MX760c
PowerEdge R7625
PowerEdge R7615
PowerEdge R6625
PowerEdge R6615
PowerEdge T350
PowerEdge T150
PowerEdge R250
PowerEdge R350
PowerEdge R650
PowerEdge XR12
PowerEdge XR11
PowerEdge R750XS
PowerEdge R650XS
PowerEdge R450
PowerEdge T550
PowerEdge R550
PowerEdge MX750c
PowerEdge C6520
PowerEdge R750XA
PowerEdge R750
PowerEdge XR4520c
PowerEdge XR4510c
PowerEdge T40
Dell EMC XC Core XC7525
PowerEdge T140
PowerEdge T340
PowerEdge R240
PowerEdge R340
Dell EMC NX440
Precision 7910 Rack
Dell EMC XC Core XC650
PowerEdge R640
PowerEdge XR2
PowerEdge R740XD2
PowerEdge R740
PowerEdge T440
PowerEdge R740XD
PowerEdge R440
PowerEdge R540
PowerEdge R940
Dell EMC Storage NX3240
PowerEdge R840
PowerEdge R940XA
PowerEdge T640
PowerEdge C6420
PowerEdge FC640
PowerEdge M640
PowerEdge M640 (for PE VRTX)
PowerEdge MX740C
PowerEdge MX840C
PowerEdge C4140
DSS 8440
Dell EMC XC Core XC6520
Dell EMC Storage NX3340
Dell EMC XC Core 6420 System
Dell EMC XC Core XC640 System
Dell EMC XC Core XC740xd System
Dell EMC XC Core XC740xd2
Dell EMC XC Core XC940 System
Dell EMC XC Core XCXR2
Dell EMC XC Core XC450
Dell EMC XC Core XC750
Dell EMC XC Core XC750xa
Precision 7920 Rack
SIMATIC MV540 H
SIMATIC MV540 S
SIMATIC MV550 H
SIMATIC MV550 S
SIMATIC MV560 U
SIMATIC MV560 X
PowerScale OneFS
Junos cRPD
FX5-OPC
IBM Observability with Instana
IBM Business Automation Workflow
Data Lakehouse
Sensor Proxy
z/Transaction Processing Facility ( z/TPF)
Ansible Automation Platform
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
IBM Watson Assistant for IBM Cloud Pak for Data
OpenShift Logging
Dell Secure Connect Gateway
Red Hat Migration Toolkit for Applications
IBM Rational Build Forge
Tenable Nessus
IBM MQ
IBM QRadar WinCollect Agent
IBM Integration Bus
NetWorker
IBM Sterling Connect:Direct for UNIX
Netcool Operations Insight
IBM MQ Operator
IBM Spectrum Copy Data Management
IBM Spectrum Conductor
PowerEdge XE8545
PowerEdge R6525
PowerEdge C6525
PowerEdge R7525
PowerEdge R7515
PowerEdge R6515
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Cloud Transformation Advisor
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Spectrum Control
IBM Elastic Storage System
IBM Safer Payments
IBM Spectrum Symphony
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Power Hardware Management Console (HMC)
IBM Workload Scheduler
IBM Spectrum Protect Plus
PowerProtect Data Manager
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
CC-Link IE TSN NZ2MHG-TSNT4
CC-Link IE TSN NZ2MHG-TSNT8F2
PCU400
SCALANCE XC208EEC
SCALANCE XB213-3LD
SCALANCE XC216EEC
SCALANCE XC216-4C G
SCALANCE XC216-4C
SCALANCE XC216-3G PoE
SCALANCE XC216
SCALANCE XC208G PoE
SCALANCE XC208G EEC
SCALANCE XC208G
SCALANCE XC206-2
SCALANCE XC208
SCALANCE XC206-2SFP G EEC
SCALANCE XC206-2SFP G
SCALANCE XB216
SCALANCE XC206-2SFP EEC
SCALANCE XC206-2SFP
SCALANCE XC206-2G PoE EEC
SCALANCE XC206-2G PoE
SCALANCE XP208PoE EEC
SIPLUS NET SCALANCE XC216-4C
SIPLUS NET SCALANCE XC208
SIPLUS NET SCALANCE XC206-2SFP
SIPLUS NET SCALANCE XC206-2
SCALANCE XR328-4C WG
SCALANCE XR326-2C PoE WG
SCALANCE XR324WG
SCALANCE XP216POE EEC
SCALANCE XP216EEC
SCALANCE XP216
SCALANCE XC224
SCALANCE XP208EEC
SCALANCE XP208
SCALANCE XF204-2BA DNA
SCALANCE XF204-2BA
SCALANCE XF204 DNA
SCALANCE XC216-4C G EEC
SCALANCE XF204
SCALANCE XC224-4C G EEC
SCALANCE XC224-4C G
SCALANCE XB208
SCALANCE XB205-3LD
SCALANCE XB205-3
SCALANCE XB213-3
SCALANCE XM416-4C
SCALANCE XR524-8C
SCALANCE XR526-8C
SCALANCE XR528-6M
SCALANCE XR552-12M
SCALANCE XM408-8C
SCALANCE XM408-4C
Dell EMC VxRail Appliance
Debian Linux
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Fedora
SUSE Enterprise Storage
IBM AIX
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
FreeBSD
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Ubuntu
openEuler
Junos OS Evolved
Open Enclave SDK
IBM App Connect Enterprise
IBM CICS TX Advanced
MobileFirst Platform
Fujitsu M10-4
Fujitsu M10-1
Fujitsu M10-4S
librdkafka
Telemetry Dashboard
Dell Hybrid Client
DB2 Data Management Console
Liquidware
IBM MQ Appliance
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
Virtualization Management Interface
cflinuxfs3
Pair
Precision 7960 Rack
Aspera faspio Gateway
ObjectScale
Dell EMC Streaming Data Platform
Secured Component Verification (SCV)
Avamar Data Store Gen5A
IBM MaaS360 Base Module
MaaS360 Configuration Utility
MaaS360 PKI Certificate Module
PowerStore T
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
Events Operator
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Spectrum Protect Client Management Service
Cognos Transformer
EMC Cloud Tiering Appliance
Wyse Device Agent
Dell Data Protection Central
Dell PowerProtect Cyber Recovery
Robotic Process Automation for Cloud Pak
API Gateway
JBoss Core Services
IBM VIOS
API Manager
IBM Integrated Analytics System
Node Health Check Operator
Self Node Remediation Operator
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Node Maintenance Operator
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
IBM DataPower Gateway
VMware Horizon Client
Dell EMC Container Storage Modules
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
QNAP QTS
JBoss Web Server
Node.js
Tenable.sc
Oracle Communications Cloud Native Core Unified Data Repository
Nessus Agent
Cloud Pak for Security (CP4S)
TeleControl Server Basic
Event Streams
Barracuda CloudGen WAN
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_1-hmac
libopenssl-1_1-devel-32bit
libopenssl-1_1-devel
libopenssl1_1
libopenssl1_1-32bit
libopenssl1_1-debuginfo
libopenssl1_1-debuginfo-32bit
openssl-1_1-debugsource
openssl-1_1-debuginfo
openssl-1_1
libopenssl1_1-hmac-32bit
openssl-1_1-doc
libopenssl1_1-32bit-debuginfo
openssl
openssl-debuginfo
openssl-debugsource
openssl-libs
openssl-devel
openssl-help
openresty-openssl111
openresty-openssl111-asan
openresty-openssl111-asan-devel
openresty-openssl111-debug
openresty-openssl111-debug-devel
openresty-openssl111-devel
openssl11
openssl-perl
openssl (Red Hat package)
openssl1.1-doc
openssl1.1-devel
openssl1.1
openssl-solibs
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libopenssl3-debuginfo
libopenssl3
libopenssl-3-devel
openssl-3
openssl-3-debuginfo
openssl-3-debugsource
libopenssl-3-devel-32bit
libopenssl3-32bit
libopenssl3-32bit-debuginfo
openssl-3-doc
libssl3 (Ubuntu package)
openssl3
dev-libs/openssl
npm
v8-devel
jbcs-httpd24-curl (Red Hat package)
nodejs (Ubuntu package)
libnode72 (Ubuntu package)
libnode-dev (Ubuntu package)
nodejs-debugsource
nodejs-full-i18n
nodejs-libs
nodejs
nodejs-debuginfo
nodejs-devel
nodejs-docs
edk2 (Ubuntu package)
edk2-devel
edk2
edk2-debugsource
edk2-debuginfo
edk2-ovmf
python3-edk2-devel
edk2-aarch64
edk2-help
edk2 (Red Hat package)
Cisco Jabber
Cisco Webex Meetings
IBM MaaS360 VPN Module
RSA Authentication Manager
IBM Security Verify Access
IBM DS8000 Hardware Management Console
IBM InfoSphere Information Server
How to mitigate CVE-2022-4450
AFS650 - update to 9.1.10
FX5-OPC - update to 1.010
Open Enclave SDK - update to 0.18.5
AFS660-C - update to 7.1.08
AFS665-B - update to 7.1.08
AFS670-V2 - update to 7.1.08
AFS670 - update to 9.1.10
AFS675 - update to 9.1.10
AFS677 - update to 9.1.10
AFR677 - update to 9.1.10
PCU400 - addressed in versions 6.6.0, 9.4.2
PCULogger tool - update to 1.2.0
API Gateway - update to February 2023
API Manager - update to February 2023
QuTS hero - update to h5.0.1.2348 build 20230324
librdkafka - update to 2.1.0
Node Health Check Operator - update to 0.4.1
Self Node Remediation Operator - update to 0.5.1
Data Lakehouse - update to 1.1.0.0
Red Hat OpenShift Serverless - update to 1.29.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.1.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Sensor Proxy - update to 1.0.7
Migration Toolkit for Containers - addressed in versions 1.7.9, 1.7.10
Multicluster Engine for Kubernetes - addressed in versions 2.0.7, 2.0.8, 2.1.6, 2.2.3
OpenShift Service Mesh - addressed in versions 2.2.7, 2.2.8, 2.3.5, 2.4.1
Migration Toolkit for Virtualization - update to 2.4.3
JBoss Core Services - update to 2.4.51 SP2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.8, 2.6.5, 2.7.3
DB2 Data Management Console - update to 3.1.13
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.11.7, 4.12.2
OpenShift Virtualization - update to 4.11.6
Red Hat OpenShift Container Platform - addressed in versions 4.11.43, 4.11.45, 4.12.22, 4.13.0, 4.13.2, 4.13.4, 4.13.5
Node Maintenance Operator - update to 5.0.1
QNAP QTS - update to 5.0.1.2346 20230322
OpenShift Logging - update to 5.5.9
JBoss Web Server - update to 5.7.3
Tenable.sc - addressed in versions 5.23.1 Patch SC-202303.1-5, 6.0.0 Patch SC-202303.1-6
Dell Secure Connect Gateway - update to 5.16
Nessus Network Monitor - update to 6.2.1
Red Hat Migration Toolkit for Applications - update to 6.1.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - update to 7.06.012
IBM Rational Build Forge - update to 8.0.0.24
Tenable Nessus - addressed in versions 8.15.9, 10.4.3, 10.5.0
Nessus Agent - addressed in versions 8.3.5, 10.3.2
Barracuda CloudGen WAN - update to 8.3.1 1093
IBM MQ - addressed in versions 9.0.0.17, 9.2.0.11, 9.3.0.5
IBM MQ Appliance - addressed in versions 9.2.0.11, 9.2.5.7, 9.3.0.5, 9.3.2.1
IBM QRadar WinCollect Agent - update to 10.1.3
IBM DataPower Gateway - addressed in versions 10.0.1.12, 10.5.0.4
Node.js - addressed in versions 14.21.3, 16.19.1, 18.14.1, 19.6.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.11.0.6, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
HP-UX OpenSSL - update to A.01.01.01t.001
Virtualization Management Interface - addressed in versions FW1020.40, FW1030.20
IBM Power System AC922 - addressed in versions FW1020.40, FW1030.20, OP940.60
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-33.el7jbcs, 0.4.10-33.el8jbcs
cflinuxfs3 - update to 0.351.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-18.el7jbcs, 1.0.0-18.el8jbcs
IBM Integrated Analytics System - update to 1.0.30.0
libopenssl1_1-hmac - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1 - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.75.1
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
openssl-1_1 - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.1d-2.75.1, 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.1d-150200.11.57.1, 1.1.1l-150400.7.22.1
openssl - addressed in versions 1.1.1f-22, 1.1.1m-16
openssl-debuginfo - addressed in versions 1.1.1f-22, 1.1.1m-16
openssl-debugsource - addressed in versions 1.1.1f-22, 1.1.1m-16
openssl-libs - addressed in versions 1.1.1f-22, 1.1.1m-16
openssl-devel - addressed in versions 1.1.1f-22, 1.1.1m-16
openssl-help - addressed in versions 1.1.1f-22, 1.1.1m-16
openresty-openssl111 - addressed in versions 1.1.1h-4, 1.1.1h-5
openresty-openssl111-asan - addressed in versions 1.1.1h-4, 1.1.1h-5
openresty-openssl111-asan-devel - addressed in versions 1.1.1h-4, 1.1.1h-5
openresty-openssl111-debug - addressed in versions 1.1.1h-4, 1.1.1h-5
openresty-openssl111-debug-devel - addressed in versions 1.1.1h-4, 1.1.1h-5
openresty-openssl111-devel - addressed in versions 1.1.1h-4, 1.1.1h-5
openssl11 - update to 1.1.1k-5.el7
openssl-libs - update to 1.1.1k-9.0.1
openssl-devel - update to 1.1.1k-9.0.1
openssl - update to 1.1.1k-9.0.1
openssl-perl - update to 1.1.1k-9.0.1
openssl (Red Hat package) - addressed in versions 1.1.1k-9.el8_6, 1.1.1k-9.el8_7, 3.0.1-46.el9_0, 3.0.1-47.el9_1
openssl-perl - update to 1.1.1m-16
openssl1.1-doc - update to 1.1.1q-6
openssl1.1-devel - update to 1.1.1q-6
openssl1.1 - update to 1.1.1q-6
openssl - update to 1.1.1t
openssl-solibs - update to 1.1.1t
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.17, 1.1.1-1ubuntu2.1~18.04.21
openssl (Debian package) - update to 1.1.1n-0+deb11u4
PowerEdge R660 - update to 1.2.1
PowerEdge R760 - update to 1.2.1
PowerEdge C6620 - update to 1.2.1
PowerEdge MX760c - update to 1.2.1
Pair - update to 1.2.3
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-14.redhat_14.el7jws, 1.2.31-14.redhat_14.el8jws, 1.2.31-14.redhat_14.el9jws
Precision 7960 Rack - update to 1.3.1
Aspera faspio Gateway - update to 1.3.2
PowerEdge R7625 - update to 1.3.11
PowerEdge R7615 - update to 1.3.11
PowerEdge R6625 - update to 1.3.11
PowerEdge R6615 - update to 1.3.11
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.18-2.el7jbcs, 1.3.18-2.el8jbcs
ObjectScale - update to 1.4.0
IBM Sterling Connect:Direct for UNIX - update to 1.5.0.1611
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-101.el7jbcs, 1.6.1-101.el8jbcs
PowerEdge T350 - update to 1.6.3
PowerEdge T150 - update to 1.6.3
PowerEdge R250 - update to 1.6.3
PowerEdge R350 - update to 1.6.3
Netcool Operations Insight - update to 1.6.10
Dell EMC Streaming Data Platform - update to 1.7.0
Dell EMC Container Storage Modules - update to 1.7.0
PowerEdge R650 - update to 1.10.2
PowerEdge XR12 - update to 1.10.2
PowerEdge XR11 - update to 1.10.2
PowerEdge R750XS - update to 1.10.2
PowerEdge R650XS - update to 1.10.2
PowerEdge R450 - update to 1.10.2
PowerEdge T550 - update to 1.10.2
PowerEdge R550 - update to 1.10.2
PowerEdge MX750c - update to 1.10.2
PowerEdge C6520 - update to 1.10.2
PowerEdge R750XA - update to 1.10.2
PowerEdge R750 - update to 1.10.2
PowerEdge XR4520c - update to 1.10.4
PowerEdge XR4510c - update to 1.10.4
Cloud Pak for Security (CP4S) - update to 1.10.12.0
PowerEdge T40 - update to 1.12.0
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-23.el7jbcs, 1.15.19-23.el8jbcs
Secured Component Verification (SCV) - update to 1.92.0
IBM MQ Operator - addressed in versions 2.0.10, 2.3.2
IBM Spectrum Copy Data Management - update to 2.2.20.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-20.el7jbcs, 2.4.0-20.el8jbcs
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-39.el7jbcs, 2.4.51-39.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-24.el7jbcs, 2.9.3-24.el8jbcs
PowerEdge XE8545 - update to 2.11.2
Dell EMC XC Core XC7525 - update to 2.11.3
PowerEdge R6525 - update to 2.11.3
PowerEdge C6525 - update to 2.11.3
PowerEdge R7525 - update to 2.11.3
PowerEdge R7515 - update to 2.11.4
PowerEdge R6515 - update to 2.11.4
PowerEdge T140 - update to 2.13.1
PowerEdge T340 - update to 2.13.1
PowerEdge R240 - update to 2.13.1
PowerEdge R340 - update to 2.13.1
Dell EMC NX440 - update to 2.13.1
Precision 7910 Rack - update to 2.17.0
Dell EMC XC Core XC650 - update to 2.18.1
PowerEdge R640 - update to 2.18.1
PowerEdge XR2 - update to 2.18.1
PowerEdge R740XD2 - update to 2.18.1
Avamar Data Store Gen5A - update to 2.18.1
PowerEdge R740 - update to 2.18.1
PowerEdge T440 - update to 2.18.1
PowerEdge R740XD - update to 2.18.1
PowerEdge R440 - update to 2.18.1
PowerEdge R540 - update to 2.18.1
PowerEdge R940 - update to 2.18.1
Dell EMC Storage NX3240 - update to 2.18.1
PowerEdge R840 - update to 2.18.1
PowerEdge R940XA - update to 2.18.1
PowerEdge T640 - update to 2.18.1
PowerEdge C6420 - update to 2.18.1
PowerEdge FC640 - update to 2.18.1
PowerEdge M640 - update to 2.18.1
PowerEdge M640 (for PE VRTX) - update to 2.18.1
PowerEdge MX740C - update to 2.18.1
PowerEdge MX840C - update to 2.18.1
PowerEdge C4140 - update to 2.18.1
DSS 8440 - update to 2.18.1
Dell EMC XC Core XC6520 - update to 2.18.1
Dell EMC Storage NX3340 - update to 2.18.1
Dell EMC XC Core 6420 System - update to 2.18.1
Dell EMC XC Core XC640 System - update to 2.18.1
Dell EMC XC Core XC740xd System - update to 2.18.1
Dell EMC XC Core XC740xd2 - update to 2.18.1
Dell EMC XC Core XC940 System - update to 2.18.1
Dell EMC XC Core XCXR2 - update to 2.18.1
Dell EMC XC Core XC450 - update to 2.18.1
Dell EMC XC Core XC750 - update to 2.18.1
Dell EMC XC Core XC750xa - update to 2.18.1
Precision 7920 Rack - update to 2.18.2
libopenssl3-debuginfo - update to 3.0.1-150400.4.17.1
libopenssl3 - update to 3.0.1-150400.4.17.1
libopenssl-3-devel - update to 3.0.1-150400.4.17.1
openssl-3 - update to 3.0.1-150400.4.17.1
openssl-3-debuginfo - update to 3.0.1-150400.4.17.1
openssl-3-debugsource - update to 3.0.1-150400.4.17.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.17.1
libopenssl3-32bit - update to 3.0.1-150400.4.17.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.17.1
openssl-3-doc - update to 3.0.1-150400.4.17.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.8, 3.0.5-2ubuntu2.1
openssl - update to 3.0.5-1
openssl3 - update to 3.0.7-5.el8.1
openssl - addressed in versions 3.0.8-1.fc36, 3.0.8-1.fc37
dev-libs/openssl - update to 3.0.10
IBM MaaS360 Base Module - update to 3.000.100
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.100
IBM MaaS360 VPN Module - update to 3.000.100
MaaS360 Configuration Utility - update to 3.000.100
MaaS360 PKI Certificate Module - update to 3.000.100
IBM MaaS360 Cloud Extender Agent - update to 3.000.100.069
TeleControl Server Basic - update to 3.1.2
SIMATIC MV540 H - update to 3.3.4
SIMATIC MV540 S - update to 3.3.4
SIMATIC MV550 H - update to 3.3.4
SIMATIC MV550 S - update to 3.3.4
SIMATIC MV560 U - update to 3.3.4
SIMATIC MV560 X - update to 3.3.4
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Transformation Advisor - update to 3.5.1
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
SCALANCE XC208EEC - update to 4.5
SCALANCE XB213-3LD - update to 4.5
SCALANCE XC216EEC - update to 4.5
SCALANCE XC216-4C G - update to 4.5
SCALANCE XC216-4C - update to 4.5
SCALANCE XC216-3G PoE - update to 4.5
SCALANCE XC216 - update to 4.5
SCALANCE XC208G PoE - update to 4.5
SCALANCE XC208G EEC - update to 4.5
SCALANCE XC208G - update to 4.5
SCALANCE XC206-2 - update to 4.5
SCALANCE XC208 - update to 4.5
SCALANCE XC206-2SFP G EEC - update to 4.5
SCALANCE XC206-2SFP G - update to 4.5
SCALANCE XB216 - update to 4.5
SCALANCE XC206-2SFP EEC - update to 4.5
SCALANCE XC206-2SFP - update to 4.5
SCALANCE XC206-2G PoE EEC - update to 4.5
SCALANCE XC206-2G PoE - update to 4.5
SCALANCE XP208PoE EEC - update to 4.5
SIPLUS NET SCALANCE XC216-4C - update to 4.5
SIPLUS NET SCALANCE XC208 - update to 4.5
SIPLUS NET SCALANCE XC206-2SFP - update to 4.5
SIPLUS NET SCALANCE XC206-2 - update to 4.5
SCALANCE XR328-4C WG - update to 4.5
SCALANCE XR326-2C PoE WG - update to 4.5
SCALANCE XR324WG - update to 4.5
SCALANCE XP216POE EEC - update to 4.5
SCALANCE XP216EEC - update to 4.5
SCALANCE XP216 - update to 4.5
SCALANCE XC224 - update to 4.5
SCALANCE XP208EEC - update to 4.5
SCALANCE XP208 - update to 4.5
SCALANCE XF204-2BA DNA - update to 4.5
SCALANCE XF204-2BA - update to 4.5
SCALANCE XF204 DNA - update to 4.5
SCALANCE XC216-4C G EEC - update to 4.5
SCALANCE XF204 - update to 4.5
SCALANCE XC224-4C G EEC - update to 4.5
SCALANCE XC224-4C G - update to 4.5
SCALANCE XB208 - update to 4.5
SCALANCE XB205-3LD - update to 4.5
SCALANCE XB205-3 - update to 4.5
SCALANCE XB213-3 - update to 4.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7.1
Events Operator - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
IBM Spectrum Control - update to 5.4.10.1
IBM Elastic Storage System - addressed in versions 6.1.2.7, 6.1.8.1
IBM Safer Payments - addressed in versions 6.3.1.04, 6.4.2.03, 6.5.0.01
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XR526-8C - update to 6.6.1
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XR552-12M - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
npm - update to 6.14.16-1.12.22.11.3
Dell EMC VxRail Appliance - update to 7.0.411
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
v8-devel - update to 7.8.279.23-1.12.22.11.3
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.0.1-1.el7jbcs, 8.0.1-1.el8jbcs
IBM Spectrum Protect Client Management Service - update to 8.1.17.2
RSA Authentication Manager - update to 8.7 Patch 4
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Power Hardware Management Console (HMC) - addressed in versions 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1
IBM Workload Scheduler - addressed in versions 9.4.0.7, 9.5.0.6, 10.1.0.3
IBM Security Verify Access - update to 10.0.6.0
IBM CICS TX Advanced - update to 10.1.0.0 ifix16
IBM Spectrum Protect Plus - update to 10.1.15
IBM Watson Explorer Foundational Components - update to 11.0.2.15
Cognos Transformer - update to 11.1.7 Fix Pack 8
Event Streams - update to 11.2.3
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
PowerScale OneFS - update to 12.0
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.11
nodejs (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.3
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.3
libnode-dev (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.3
nodejs-debugsource - update to 12.22.11-3
nodejs-full-i18n - update to 12.22.11-3
nodejs-libs - update to 12.22.11-3
nodejs - update to 12.22.11-3
nodejs-debuginfo - update to 12.22.11-3
nodejs-devel - update to 12.22.11-3
nodejs-docs - update to 12.22.11-3
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
Wyse Device Agent - update to 14.6.10.18
Dell Data Protection Central - update to 19.11.0-2
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.21, 22.0.2.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.4, 23.0.5
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
IBM DS8000 Hardware Management Console - update to 89.33.34.0
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-devel - update to 202002-15
edk2 - update to 202002-15
edk2-debugsource - update to 202002-15
edk2-debuginfo - update to 202002-15
edk2-ovmf - update to 202002-15
python3-edk2-devel - update to 202002-15
edk2-aarch64 - update to 202002-15
edk2-help - update to 202002-15
edk2-ovmf - update to 20220126gitbb1bba3d77-4
edk2-aarch64 - update to 20220126gitbb1bba3d77-4
edk2 (Red Hat package) - addressed in versions 20220126gitbb1bba3d77-4.el8, 20221207gitfff6d81270b5-9.el9_2
edk2 - addressed in versions 20221117gitfff6d81270b5-13.fc36, 20221117gitfff6d81270b5-13.fc37, 20221117gitfff6d81270b5-14.fc36
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-3
- Slackware Linux update for openssl
- Debian update for openssl
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Open Enclave SDK update for OpenSSL
- FreeBSD update for OpenSSL
- Node.js update for OpenSSL
- Red Hat Enterprise Linux 9 update for openssl
- Multiple vulnerabilities in IBM Business Automation Workflow Configuration Editor
- Multiple vulnerabilities in Tenable.sc
- Multiple vulnerabilities in Tenable Nessus
- Barracuda CloudGen WAN update for OpenSSL
- Double free in IBM Sterling Connect:Express for UNIX
- IBM DataPower Gateway update for OpenSSL
- Multiple vulnerabilities in Tenable Nessus
- IBM Aspera faspio Gateway update for OpenSSL
- Multiple vulnerabilities in Nessus Agent 8.x
- Multiple vulnerabilities in Nessus Agent 10.x
- Multiple vulnerabilities in QRadar WinCollect Agent
- Red Hat Enterprise Linux 9.0 Extended Update Support update for openssl
- Multiple vulnerabilities in Siemens SCALANCE W1750D Devices
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Tenable Sensor Proxy
- Multiple vulnerabilities in IBM Spectrum Protect Backup-Archive Client
- Red Hat Enterprise Linux 8 update for openssl
- IBM AIX and VIOS update for OpenSSL
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.5
- QNAP QTS and QuTS hero update for OpenSSL
- Multiple vulnerabilities in API Gateway and API Manager
- Multiple vulnerabilities in z/Transaction Processing Facility
- Multiple vulnerabilities in librdkafka
- Multiple vulnerabilities in IBM Watson Explorer
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in IBM MobileFirst Foundation
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.0
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.12
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.11
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM MQ Operator
- IBM App Connect Enterprise Certified Container update for OpenSSL
- Multiple vulnerabilities in IBM MQ
- IBM MQ Appliance update for OpenSSL
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.0
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.5
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Red Hat Enterprise Linux 9 update for edk2
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in IBM CICS TX Advanced
- Red Hat Enterprise Linux 8 update for edk2
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Secondary Scheduler Operator for Red Hat OpenShift
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Power HMC
- VMware Tanzu Platform Automation Toolkit update for OpenSSL
- Dell PowerEdge server update for OpenSSL
- Multiple vulnerabilities in HPE HP-UX Using OpenSSL
- Red Hat Enterprise Linux 8.6 Extended Update Support update for openssl
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Red Hat JBoss Core Services update for Apache HTTP Server
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway, Configuration Utility, VPN, Certificate and Base Module
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Double free in IBM Workload Scheduler
- OpenShift Container Platform 4.11 update for golang
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.2
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- OpenShift Container Platform 4.13 update for golang
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Security Verify Access Appliance
- Multiple vulnerabilities in IBM DS8000 Hardware Management Console (HMC)
- Multiple vulnerabilities in Siemens SIMATIC MV500 Devices
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.2
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.3
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.4
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Dell Hybrid Client
- Double free in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Container Storage Modules
- Double free in IBM Elastic Storage System
- Fedora 37 update for openssl
- Fedora 36 update for openssl
- Fedora 37 update for edk2
- Fedora 36 update for edk2
- Fedora EPEL 8 update for openssl3
- Fedora 36 update for edk2
- Fedora EPEL 7 update for openssl11
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Dell Precision Rack
- Dell PowerEdge T40 Mini Tower Server update for OpenSSL
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Double free in IBM Events Operator
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in IBM Observability with Instana (Self-hosted on Docker)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Multiple vulnerabilities in Red Hat Self Node Remediation Operator 0.5
- Multiple vulnerabilities in Red Hat Node Maintenance Operator 5.0
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Node Health Check Operator 0.4
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Siemens SCALANCE XB-200 / XC-200 / XP-200 / XF-200BA / XR-300WG Family
- Ubuntu update for nodejs
- Multiple vulnerabilities in Dell PowerScale OneFS
- Multiple vulnerabilities in Mitsubishi Electric Factory Automation Products
- Multiple vulnerabilities in Fujitsu M12-2S
- Multiple vulnerabilities in Fujitsu M12-2
- Multiple vulnerabilities in Fujitsu M12-1
- Multiple vulnerabilities in Fujitsu M10-4S
- Multiple vulnerabilities in Fujitsu M10-4
- Multiple vulnerabilities in Fujitsu M10-1
- Multiple vulnerabilities in IBM Virtualization Management Interface
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Transformer
- openEuler update for edk2
- openEuler update for nodejs
- openEuler update for openssl
- openEuler 22.03 LTS SP1 update for openssl
- Multiple vulnerabilities in Siemens Telecontrol Server Basic
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Double free in IBM Power System
- Multiple vulnerabilities in Siemens SCALANCE XM-400/XR-500
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell PowerStore Family
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in Hitachi Energy AFS/AFR Series Products
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell Pair
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Integrated Analytics System
- openEuler 22.03 LTS SP1 update for openresty-openssl111
- openEuler 22.03 LTS SP3 update for openresty-openssl111
- Multiple vulnerabilities in Dell Avamar Data Store Gen5a
- Multiple vulnerabilities in Hitachi Energy PCU400 and PCULogger
- Anolis OS update for openssl
- Anolis OS update for edk2
- Dell Wyse Device Agent update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Dell NetWorker update for OpenSSL
- Anolis OS update for openssl1.1
- Ubuntu update for edk2
- Ubuntu update for edk2
- Multiple vulnerabilities in IBM DB2 Data Management Console