Improper Verification of Cryptographic Signature in OpenSSL - CVE-2023-0465
Published: March 28, 2023 / Updated: October 11, 2023
Vulnerability identifier: #VU74148
CSH Severity: Low
CVSS v4 BT: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-0465
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error when validating certificate policies in leaf certificates. A remote attacker that controls a malicious CA server can issue a certificate that will be validated by the application.
Affected software
OpenSSL
Oracle Linux
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Junos OS Evolved
Cisco NX-OS
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
cflinuxfs3
Pair
ObjectScale
Storage Defender – Data Protect
IBM Aspera Shares
Secured Component Verification (SCV)
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Events Operator
MobileFirst Platform
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
IBM Workload Automation
Cognos Transformer
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
VMware Tanzu Application Service for VMs
Isolation Segment
Data Lakehouse
cert-manager Operator for Red Hat OpenShift
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM QRadar WinCollect Agent
NetWorker
Sensor Proxy
IBM MQ Operator
IBM Spectrum Conductor
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Safer Payments
IBM Spectrum Symphony
IBM Rational ClearCase
IBM Rational ClearQuest
InfoSphere Master Data Management
PowerProtect Data Manager
API Manager
API Gateway
JBoss Core Services
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform
VMware Horizon Client
JBoss Web Server
SecurityCenter
Nessus Agent
TeleControl Server Basic
Event Streams
NetWorker Management Console
IBM InfoSphere Information Server
Cisco Jabber
Cisco Webex Meetings
libssl1.0.0 (Ubuntu package)
openssl (Ubuntu package)
libssl-doc (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8-hmac
libopenssl0_9_8-32bit
openssl
libopenssl0_9_8
openssl-doc
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo-32bit
libopenssl0_9_8-debuginfo
compat-openssl098-debugsource
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0
openssl1-doc
openssl1
libopenssl1-devel
libopenssl1_0_0-32bit
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
openssl-debugsource
libopenssl-devel
libopenssl1_0_0-hmac-32bit
libopenssl1_0_0-hmac
openssl-debuginfo
openssl1.0 (Ubuntu package)
openssl-1_0_0-doc
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-32bit-debuginfo
libopenssl-1_0_0-devel
openssl-1_0_0-cavs
openssl-1_0_0-debugsource
libopenssl1_0_0-steam-debuginfo
libopenssl10
libopenssl-1_0_0-devel-32bit
openssl-1_0_0
openssl-1_0_0-cavs-debuginfo
libopenssl10-debuginfo
libopenssl1_0_0-steam
openssl-1_0_0-debuginfo
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel-32bit
openssl-1_1-debugsource
openssl-1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl-1_1-devel
libopenssl1_1-debuginfo
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-help
openssl-libs
openssl-devel
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libopenssl-3-devel-32bit
libopenssl3-debuginfo
openssl-3-debugsource
libopenssl3-32bit
openssl-3
libopenssl3
libopenssl-3-devel
openssl-3-debuginfo
openssl-3-doc
libopenssl3-32bit-debuginfo
libssl3 (Ubuntu package)
openssl (Red Hat package)
dev-libs/openssl
npm
v8-devel
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
nodejs
nodejs-debugsource
nodejs-full-i18n
nodejs-libs
nodejs-devel
nodejs-debuginfo
nodejs-docs
shim
shim-debuginfo
shim-debugsource
edk2 (Ubuntu package)
edk2
edk2-debuginfo
edk2-ovmf
edk2-aarch64
python3-edk2-devel
edk2-help
edk2-debugsource
edk2-devel
Network Observability plugin for the Openshift Console
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
IBM Cloud Pak System
RecoverPoint for VMs
SCALANCE XR526-8C
SCALANCE XM408-4C
SCALANCE XM408-8C
SCALANCE XM416-4C
SCALANCE XR524-8C
SCALANCE XR528-6M
SCALANCE XR552-12M
IBM Security Verify Access
IBM CICS TX Advanced
Oracle Linux
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Junos OS Evolved
Cisco NX-OS
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
cflinuxfs3
Pair
ObjectScale
Storage Defender – Data Protect
IBM Aspera Shares
Secured Component Verification (SCV)
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Events Operator
MobileFirst Platform
Storage Protect for Virtual Environments: Data Protection for VMware
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
IBM Workload Automation
Cognos Transformer
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
VMware Tanzu Application Service for VMs
Isolation Segment
Data Lakehouse
cert-manager Operator for Red Hat OpenShift
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM QRadar WinCollect Agent
NetWorker
Sensor Proxy
IBM MQ Operator
IBM Spectrum Conductor
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Safer Payments
IBM Spectrum Symphony
IBM Rational ClearCase
IBM Rational ClearQuest
InfoSphere Master Data Management
PowerProtect Data Manager
API Manager
API Gateway
JBoss Core Services
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
VMware Tanzu Operations Manager
Red Hat OpenShift Container Platform
VMware Horizon Client
JBoss Web Server
SecurityCenter
Nessus Agent
TeleControl Server Basic
Event Streams
NetWorker Management Console
IBM InfoSphere Information Server
Cisco Jabber
Cisco Webex Meetings
libssl1.0.0 (Ubuntu package)
openssl (Ubuntu package)
libssl-doc (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8-hmac
libopenssl0_9_8-32bit
openssl
libopenssl0_9_8
openssl-doc
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo-32bit
libopenssl0_9_8-debuginfo
compat-openssl098-debugsource
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0
openssl1-doc
openssl1
libopenssl1-devel
libopenssl1_0_0-32bit
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
openssl-debugsource
libopenssl-devel
libopenssl1_0_0-hmac-32bit
libopenssl1_0_0-hmac
openssl-debuginfo
openssl1.0 (Ubuntu package)
openssl-1_0_0-doc
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-32bit-debuginfo
libopenssl-1_0_0-devel
openssl-1_0_0-cavs
openssl-1_0_0-debugsource
libopenssl1_0_0-steam-debuginfo
libopenssl10
libopenssl-1_0_0-devel-32bit
openssl-1_0_0
openssl-1_0_0-cavs-debuginfo
libopenssl10-debuginfo
libopenssl1_0_0-steam
openssl-1_0_0-debuginfo
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel-32bit
openssl-1_1-debugsource
openssl-1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl-1_1-devel
libopenssl1_1-debuginfo
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-help
openssl-libs
openssl-devel
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libopenssl-3-devel-32bit
libopenssl3-debuginfo
openssl-3-debugsource
libopenssl3-32bit
openssl-3
libopenssl3
libopenssl-3-devel
openssl-3-debuginfo
openssl-3-doc
libopenssl3-32bit-debuginfo
libssl3 (Ubuntu package)
openssl (Red Hat package)
dev-libs/openssl
npm
v8-devel
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
nodejs
nodejs-debugsource
nodejs-full-i18n
nodejs-libs
nodejs-devel
nodejs-debuginfo
nodejs-docs
shim
shim-debuginfo
shim-debugsource
edk2 (Ubuntu package)
edk2
edk2-debuginfo
edk2-ovmf
edk2-aarch64
python3-edk2-devel
edk2-help
edk2-debugsource
edk2-devel
Network Observability plugin for the Openshift Console
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
IBM Cloud Pak System
RecoverPoint for VMs
SCALANCE XR526-8C
SCALANCE XM408-4C
SCALANCE XM408-8C
SCALANCE XM416-4C
SCALANCE XR524-8C
SCALANCE XR528-6M
SCALANCE XR552-12M
IBM Security Verify Access
IBM CICS TX Advanced
How to mitigate CVE-2023-0465
Install update from vendor's website.
OpenSSL - addressed in versions 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1
API Manager - update to August 2023
API Gateway - update to August 2023
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
JBoss Web Server - update to 5.7.7
Dell Secure Connect Gateway - update to 5.16
SecurityCenter - update to 6.2.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Nessus Agent - update to 10.4.1
IBM QRadar WinCollect Agent - update to 10.1.6
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.12
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
libssl-doc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.66.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.66.1, 0.9.8j-106.48.1
openssl - addressed in versions 0.9.8j-0.106.66.1, 1.0.2j-60.92.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.66.1, 0.9.8j-106.48.1
openssl-doc - addressed in versions 0.9.8j-0.106.66.1, 1.0.2j-60.92.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.66.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.48.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.48.1
compat-openssl098-debugsource - update to 0.9.8j-106.48.1
cflinuxfs3 - update to 0.364.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.62.1, 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
openssl1-doc - update to 1.0.1g-0.58.62.1
openssl1 - update to 1.0.1g-0.58.62.1
libopenssl1-devel - update to 1.0.1g-0.58.62.1
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.62.1, 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-debuginfo-32bit - update to 1.0.2j-60.92.1
openssl-debugsource - update to 1.0.2j-60.92.1
libopenssl-devel - update to 1.0.2j-60.92.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
openssl-debuginfo - update to 1.0.2j-60.92.1
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.12
openssl-1_0_0-doc - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl-1_0_0-devel - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-debugsource - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl10 - update to 1.0.2p-150000.3.73.1
libopenssl-1_0_0-devel-32bit - update to 1.0.2p-150000.3.73.1
openssl-1_0_0 - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-debuginfo - update to 1.0.2p-150000.3.73.1
Sensor Proxy - update to 1.0.8
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1 - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.81.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-help - update to 1.1.1f-23
openssl - update to 1.1.1f-23
openssl-libs - update to 1.1.1f-23
openssl-devel - update to 1.1.1f-23
openssl-debugsource - update to 1.1.1f-23
openssl-debuginfo - update to 1.1.1f-23
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22
openssl (Debian package) - update to 1.1.1n-0+deb11u5
Pair - update to 1.2.3
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
Network Observability plugin for the Openshift Console - update to 1.3.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.1
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
IBM Aspera Shares - update to 1.10.0 PL4
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.10.57, 3.0.8
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.23.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.23.1
openssl-3-debugsource - update to 3.0.1-150400.4.23.1
libopenssl3-32bit - update to 3.0.1-150400.4.23.1
openssl-3 - update to 3.0.1-150400.4.23.1
libopenssl3 - update to 3.0.1-150400.4.23.1
libopenssl-3-devel - update to 3.0.1-150400.4.23.1
openssl-3-debuginfo - update to 3.0.1-150400.4.23.1
openssl-3-doc - update to 3.0.1-150400.4.23.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.23.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
dev-libs/openssl - update to 3.0.10
TeleControl Server Basic - update to 3.1.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Enterprise SONiC - update to 4.1.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Events Operator - update to 5.1.0
IBM Spectrum Control - update to 5.4.11
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Safer Payments - addressed in versions 6.3.1.05, 6.4.2.04, 6.5.0.02
SCALANCE XR526-8C - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XR552-12M - update to 6.6.1
npm - addressed in versions 6.14.16-1.12.22.11.7, 6.14.16-1.12.22.11.9
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
v8-devel - addressed in versions 7.8.279.23-1.12.22.11.7, 7.8.279.23-1.12.22.11.9
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.22.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
FOS Firmware - addressed in versions 9.1.1d, 9.2.0b, 9.2.1
Cisco NX-OS - update to 9.4(1a)
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - update to 10.1.0.0 ifix20
Cognos Transformer - update to 11.1.7 Fix Pack 8
Event Streams - update to 11.5.1
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
nodejs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debugsource - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-full-i18n - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-libs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-devel - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debuginfo - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-docs - addressed in versions 12.22.11-7, 12.22.11-9
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.22
shim - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debuginfo - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debugsource - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2-ovmf - update to 202002-18
edk2-aarch64 - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-help - update to 202002-18
edk2-debugsource - update to 202002-18
edk2-devel - update to 202002-18
API Manager - update to August 2023
API Gateway - update to August 2023
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
JBoss Web Server - update to 5.7.7
Dell Secure Connect Gateway - update to 5.16
SecurityCenter - update to 6.2.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Nessus Agent - update to 10.4.1
IBM QRadar WinCollect Agent - update to 10.1.6
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.12
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
libssl-doc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.66.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.66.1, 0.9.8j-106.48.1
openssl - addressed in versions 0.9.8j-0.106.66.1, 1.0.2j-60.92.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.66.1, 0.9.8j-106.48.1
openssl-doc - addressed in versions 0.9.8j-0.106.66.1, 1.0.2j-60.92.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.66.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.48.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.48.1
compat-openssl098-debugsource - update to 0.9.8j-106.48.1
cflinuxfs3 - update to 0.364.0
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.62.1, 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
openssl1-doc - update to 1.0.1g-0.58.62.1
openssl1 - update to 1.0.1g-0.58.62.1
libopenssl1-devel - update to 1.0.1g-0.58.62.1
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.62.1, 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-debuginfo-32bit - update to 1.0.2j-60.92.1
openssl-debugsource - update to 1.0.2j-60.92.1
libopenssl-devel - update to 1.0.2j-60.92.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.92.1, 1.0.2p-150000.3.73.1
openssl-debuginfo - update to 1.0.2j-60.92.1
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.12
openssl-1_0_0-doc - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl-1_0_0-devel - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-debugsource - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl10 - update to 1.0.2p-150000.3.73.1
libopenssl-1_0_0-devel-32bit - update to 1.0.2p-150000.3.73.1
openssl-1_0_0 - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.73.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.73.1
openssl-1_0_0-debuginfo - update to 1.0.2p-150000.3.73.1
Sensor Proxy - update to 1.0.8
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-1_1 - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.48.1, 1.1.1d-2.81.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.81.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.34.1
openssl-help - update to 1.1.1f-23
openssl - update to 1.1.1f-23
openssl-libs - update to 1.1.1f-23
openssl-devel - update to 1.1.1f-23
openssl-debugsource - update to 1.1.1f-23
openssl-debuginfo - update to 1.1.1f-23
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22
openssl (Debian package) - update to 1.1.1n-0+deb11u5
Pair - update to 1.2.3
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
Network Observability plugin for the Openshift Console - update to 1.3.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.1
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
IBM Aspera Shares - update to 1.10.0 PL4
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
IBM MQ Operator - addressed in versions 2.0.13, 2.4.1
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.10.57, 3.0.8
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.23.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.23.1
openssl-3-debugsource - update to 3.0.1-150400.4.23.1
libopenssl3-32bit - update to 3.0.1-150400.4.23.1
openssl-3 - update to 3.0.1-150400.4.23.1
libopenssl3 - update to 3.0.1-150400.4.23.1
libopenssl-3-devel - update to 3.0.1-150400.4.23.1
openssl-3-debuginfo - update to 3.0.1-150400.4.23.1
openssl-3-doc - update to 3.0.1-150400.4.23.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.23.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
dev-libs/openssl - update to 3.0.10
TeleControl Server Basic - update to 3.1.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Enterprise SONiC - update to 4.1.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Events Operator - update to 5.1.0
IBM Spectrum Control - update to 5.4.11
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Safer Payments - addressed in versions 6.3.1.05, 6.4.2.04, 6.5.0.02
SCALANCE XR526-8C - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XR552-12M - update to 6.6.1
npm - addressed in versions 6.14.16-1.12.22.11.7, 6.14.16-1.12.22.11.9
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
v8-devel - addressed in versions 7.8.279.23-1.12.22.11.7, 7.8.279.23-1.12.22.11.9
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.22.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
FOS Firmware - addressed in versions 9.1.1d, 9.2.0b, 9.2.1
Cisco NX-OS - update to 9.4(1a)
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - update to 10.1.0.0 ifix20
Cognos Transformer - update to 11.1.7 Fix Pack 8
Event Streams - update to 11.5.1
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
nodejs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debugsource - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-full-i18n - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-libs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-devel - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debuginfo - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-docs - addressed in versions 12.22.11-7, 12.22.11-9
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.22
shim - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debuginfo - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debugsource - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2-ovmf - update to 202002-18
edk2-aarch64 - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-help - update to 202002-18
edk2-debugsource - update to 202002-18
edk2-devel - update to 202002-18
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-3
- SUSE update for openssl-1_1
- SUSE update for openssl
- SUSE update for compat-openssl098
- SUSE update for openssl-1_1
- SUSE update for openssl-1_0_0
- SUSE update for openssl1
- SUSE update for openssl
- Cloud Foundry Foundation cflinuxfs3 update for OpenSSL
- Ubuntu update for openssl
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- VMware Tanzu products update for OpenSSL
- Debian update for openssl
- Amazon Linux AMI update for openssl
- Red Hat Enterprise Linux 9 update for openssl
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Tenable Nessus Agent
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM QRadar Wincollect
- Tenable Security Center update for OpenSSL
- Tenable Security Center 5 update for OpenSSL
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Improper verification of cryptographic signature in IBM CICS TX Advanced
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM MobileFirst Platform
- Multiple vulnerabilities in Tenable Sensor Proxy
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in IBM i
- Axway API Gateway and API Manager update for OpenSSL
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in JBoss Enterprise Web Server 5 for RHEL 7, 8, and 9
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in InfoSphere Information Server
- Multiple vulnerabilities in Dell Networker
- Dell Platform BIOS update for OpenSSL
- Gentoo update for OpenSSL
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Transformer
- openEuler 20.03 LTS SP1 update for nodejs
- openEuler 22.03 LTS update for nodejs
- openEuler 22.03 LTS SP1 update for nodejs
- openEuler 22.03 LTS SP2 update for nodejs
- openEuler 22.03 LTS SP3 update for nodejs
- openEuler 22.03 LTS update for shim
- openEuler 22.03 LTS SP1 update for shim
- openEuler 22.03 LTS SP2 update for shim
- openEuler 22.03 LTS SP3 update for shim
- openEuler 20.03 LTS SP1 update for shim
- openEuler update for edk2
- openEuler 20.03 LTS SP4 update for shim
- openEuler 20.03 LTS SP4 update for nodejs
- Multiple vulnerabilities in NX-OS Firmware
- openEuler update for openssl
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for VMware
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for Microsoft Hyper-V
- Multiple vulnerabilities in IBM Storage Protect Client
- Multiple vulnerabilities in Siemens Telecontrol Server Basic
- Multiple vulnerabilities in IBM Workload Automation
- Multiple vulnerabilities in IBM FOS firmware
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Siemens SCALANCE XM-400/XR-500
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Dell Pair
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Aspera Shares
- Multiple vulnerabilities in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Events Operator
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in Dell NetWorker and NetWorker Management Console
- Dell NetWorker update for OpenSSL
- Ubuntu update for edk2
- Ubuntu update for edk2