Resource management error in OpenSSL - CVE-2023-2650
Published: May 30, 2023 / Updated: October 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS subsystems with no message size limit. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
CC-Link IE TSN NZ2MHG-TSNT4
CC-Link IE TSN NZ2MHG-TSNT8F2
SCALANCE XF204
SCALANCE XF204 DNA
SCALANCE XF204-2BA
SCALANCE XF204-2BA DNA
SCALANCE XP208
SCALANCE XP208EEC
SCALANCE XP208PoE EEC
SCALANCE XP216
SCALANCE XP216EEC
SCALANCE XP216POE EEC
SCALANCE XR324WG
SCALANCE XR326-2C PoE WG
SCALANCE XR328-4C WG
SIPLUS NET SCALANCE XC206-2
SIPLUS NET SCALANCE XC206-2SFP
SIPLUS NET SCALANCE XC208
SIPLUS NET SCALANCE XC216-4C
SCALANCE XC208G PoE
SCALANCE XC224-4C G
SCALANCE XB205-3
SCALANCE XB205-3LD
SCALANCE XB208
SCALANCE XB213-3
SCALANCE XB213-3LD
SCALANCE XB216
SCALANCE XC206-2
SCALANCE XC206-2G PoE
SCALANCE XC206-2G PoE EEC
SCALANCE XC206-2SFP
SCALANCE XC206-2SFP EEC
SCALANCE XC206-2SFP G
SCALANCE XC206-2SFP G EEC
SCALANCE XC208EEC
SCALANCE XC224-4C G EEC
SCALANCE XC224
SCALANCE XC216EEC
SCALANCE XC216-4C G EEC
SCALANCE XC216-4C G
SCALANCE XC216-4C
SCALANCE XC216-3G PoE
SCALANCE XC216
SCALANCE XC208G EEC
SCALANCE XC208G
SCALANCE XC208
Dell EMC VxRail Appliance
Oracle Linux
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
F5OS
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Oracle Solaris
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Cisco NX-OS
Cognos Dashboards on Cloud Pak for Data
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Telemetry Dashboard
Liquidware
HPE OneView
Citrix Workspace App
Webex App VDI
ObjectScale
IBM Aspera Shares
Secured Component Verification (SCV)
IBM Planning Analytics Workspace
EMC ECS
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Events Operator
Storage Ceph
MobileFirst Platform
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
Index Engines CyberSense
IBM MQ Appliance
IBM Workload Automation
Cognos Transformer
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
Storage Insights - Data Collector
Isolation Segment
VMware Tanzu Application Service for VMs
Data Lakehouse
cert-manager Operator for Red Hat OpenShift
IBM Cloud Pak for Data System
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Rational Build Forge
Oracle HTTP Server
NetWorker
Sensor Proxy
IBM Spectrum Conductor
IBM MaaS360 Mobile Enterprise Gateway
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Spectrum Control
Session Smart Router
IBM Safer Payments
IBM Spectrum Symphony
IBM MQ for HPE NonStop
IBM MQ
IBM Rational ClearCase
IBM Rational ClearQuest
InfoSphere Master Data Management
PowerProtect Data Manager
Juniper Cloud Native Router
BIG-IP
LANTIME Operating System Firmware (LTOS)
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
Junos cRPD
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
VMware Tanzu Operations Manager
QRadar Suite
Dell EMC NetWorker vProxy
Red Hat OpenShift Container Platform
Traffix SDC
JD Edwards EnterpriseOne Tools
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
VMware Horizon Client
IBM DataPower Gateway
JBoss Web Server
MySQL Server
MySQL Enterprise Monitor
IBM InfoSphere Information Server
Oracle Essbase
SecurityCenter
BIG-IQ Centralized Management
IBM Security Verify Access
MySQL Workbench
IBM App Connect Enterprise
Nessus Agent
Event Streams
Cisco Jabber
Cisco Webex Meetings
openssl (Ubuntu package)
libssl1.0.0 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8
libopenssl0_9_8-hmac
openssl
libopenssl0_9_8-32bit
openssl-doc
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo-32bit
compat-openssl098-debugsource
libopenssl0_9_8-debuginfo
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-32bit
libopenssl1-devel
openssl1-doc
libopenssl1_0_0
openssl1
libopenssl1_0_0-hmac
openssl-debuginfo
libopenssl1_0_0-debuginfo
openssl-debugsource
libopenssl1_0_0-debuginfo-32bit
libopenssl-devel
libopenssl1_0_0-hmac-32bit
libopenssl-1_0_0-devel
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-doc
openssl-1_0_0-debuginfo
openssl-1_0_0
openssl-1_0_0-debugsource
libopenssl1_0_0-steam-debuginfo
libopenssl10
libopenssl10-debuginfo
libopenssl1_0_0-steam
openssl-1_0_0-cavs
openssl-1_0_0-cavs-debuginfo
libopenssl1_0_0-32bit-debuginfo
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_1-hmac
openssl-1_1-debugsource
libopenssl1_1
openssl-1_1-debuginfo
libopenssl1_1-hmac-32bit
libopenssl1_1-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel
libopenssl1_1-debuginfo
openssl-1_1
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-devel
openssl-libs
openssl-help
libopenssl-1_1-devel-64bit
libopenssl1_1-64bit
libopenssl1_1-hmac-64bit
libopenssl1_1-64bit-debuginfo
openssl-perl
openssl-solibs
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libssl3 (Ubuntu package)
openssl (Red Hat package)
libopenssl3-32bit-debuginfo
libopenssl3-32bit
openssl-3-debugsource
openssl-3
openssl-3-debuginfo
libopenssl3
libopenssl3-debuginfo
libopenssl-3-devel
libopenssl-3-devel-32bit
openssl-3-doc
libopenssl3-64bit-debuginfo
libopenssl-3-devel-64bit
libopenssl3-64bit
dev-libs/openssl
mysql-server-8.0 (Ubuntu package)
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
libnode64 (Ubuntu package)
nodejs (Ubuntu package)
libnode72 (Ubuntu package)
shim
shim-debuginfo
shim-debugsource
libnode108 (Ubuntu package)
edk2 (Ubuntu package)
edk2
edk2-ovmf
edk2-aarch64
python3-edk2-devel
edk2-help
edk2-debugsource
edk2-devel
edk2-debuginfo
edk2 (Red Hat package)
Network Observability plugin for the Openshift Console
IBM Cloud Pak System
JBoss Core Services
IBM MaaS360 VPN Module
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
RecoverPoint for VMs
RSA Authentication Manager
How to mitigate CVE-2023-2650
CC-Link IE TSN NZ2MHG-TSNT4 - update to 06
CC-Link IE TSN NZ2MHG-TSNT8F2 - update to 06
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
JBoss Web Server - update to 5.7.7
MySQL Server - addressed in versions 5.7.43, 8.0.34
SecurityCenter - update to 6.2.0
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
HPE OneView - update to 8.50.00
LANTIME Operating System Firmware (LTOS) - update to 7.08.002
IBM Rational Build Forge - update to 8.0.0.25
MySQL Workbench - update to 8.0.34
JD Edwards EnterpriseOne Tools - update to 9.2.8.0
Nessus Agent - update to 10.4.1
IBM Watson Explorer Foundational Components - update to 11.0.2.16
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.11.0.6, 19.12.0.2
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
openssl (Ubuntu package) - update to Ubuntu Pro
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.13
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.71.1, 0.9.8j-106.51.1
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.71.1
openssl - addressed in versions 0.9.8j-0.106.71.1, 1.0.2j-60.95.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.71.1, 0.9.8j-106.51.1
openssl-doc - addressed in versions 0.9.8j-0.106.71.1, 1.0.2j-60.95.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.71.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.51.1
compat-openssl098-debugsource - update to 0.9.8j-106.51.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.51.1
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.67.1, 1.0.2j-60.95.1, 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
libopenssl1-devel - update to 1.0.1g-0.58.67.1
openssl1-doc - update to 1.0.1g-0.58.67.1
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.67.1, 1.0.2j-60.95.1, 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl1 - update to 1.0.1g-0.58.67.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.95.1, 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-debuginfo - update to 1.0.2j-60.95.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.95.1, 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-debugsource - update to 1.0.2j-60.95.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.95.1, 1.0.2p-3.75.1
libopenssl-devel - update to 1.0.2j-60.95.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.95.1, 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.75.1, 1.0.2p-150000.3.76.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.76.1
libopenssl10 - update to 1.0.2p-150000.3.76.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.76.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.76.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.76.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.76.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.76.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.76.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.76.1
Sensor Proxy - update to 1.0.8
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
openssl-1_1 - addressed in versions 1.1.0i-150100.14.51.1, 1.1.1d-2.84.1, 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.84.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.65.1, 1.1.1l-150400.7.37.1, 1.1.1l-150500.17.6.1
openssl-debugsource - addressed in versions 1.1.1f-25, 1.1.1m-20
openssl-devel - addressed in versions 1.1.1f-25, 1.1.1m-20
openssl - addressed in versions 1.1.1f-25, 1.1.1m-20
openssl-libs - addressed in versions 1.1.1f-25, 1.1.1m-20
openssl-debuginfo - addressed in versions 1.1.1f-25, 1.1.1m-20
openssl-help - addressed in versions 1.1.1f-25, 1.1.1m-20
libopenssl-1_1-devel-64bit - update to 1.1.1l-150500.17.6.1
libopenssl1_1-64bit - update to 1.1.1l-150500.17.6.1
libopenssl1_1-hmac-64bit - update to 1.1.1l-150500.17.6.1
libopenssl1_1-64bit-debuginfo - update to 1.1.1l-150500.17.6.1
openssl-perl - update to 1.1.1m-20
openssl-solibs - update to 1.1.1u
openssl - update to 1.1.1u
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.19, 1.1.1-1ubuntu2.1~18.04.23
openssl (Debian package) - update to 1.1.1n-0+deb11u5
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
Network Observability plugin for the Openshift Console - update to 1.3.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
IBM Aspera Shares - update to 1.10.0 PL4
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.10.59, 3.0.11
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.10, 3.0.5-2ubuntu2.3, 3.0.8-1ubuntu1.2
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3 - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3 - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.26.1, 3.0.8-150500.5.3.1
libopenssl3-64bit-debuginfo - update to 3.0.8-150500.5.3.1
libopenssl-3-devel-64bit - update to 3.0.8-150500.5.3.1
libopenssl3-64bit - update to 3.0.8-150500.5.3.1
dev-libs/openssl - update to 3.0.10
IBM MaaS360 VPN Module - update to 3.000.200
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.200
EMC ECS - update to 3.8.0.4
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Enterprise SONiC - update to 4.1.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
SCALANCE XF204 - update to 4.5
SCALANCE XF204 DNA - update to 4.5
SCALANCE XF204-2BA - update to 4.5
SCALANCE XF204-2BA DNA - update to 4.5
SCALANCE XP208 - update to 4.5
SCALANCE XP208EEC - update to 4.5
SCALANCE XP208PoE EEC - update to 4.5
SCALANCE XP216 - update to 4.5
SCALANCE XP216EEC - update to 4.5
SCALANCE XP216POE EEC - update to 4.5
SCALANCE XR324WG - update to 4.5
SCALANCE XR326-2C PoE WG - update to 4.5
SCALANCE XR328-4C WG - update to 4.5
SIPLUS NET SCALANCE XC206-2 - update to 4.5
SIPLUS NET SCALANCE XC206-2SFP - update to 4.5
SIPLUS NET SCALANCE XC208 - update to 4.5
SIPLUS NET SCALANCE XC216-4C - update to 4.5
SCALANCE XC208G PoE - update to 4.5
SCALANCE XC224-4C G - update to 4.5
SCALANCE XB205-3 - update to 4.5
SCALANCE XB205-3LD - update to 4.5
SCALANCE XB208 - update to 4.5
SCALANCE XB213-3 - update to 4.5
SCALANCE XB213-3LD - update to 4.5
SCALANCE XB216 - update to 4.5
SCALANCE XC206-2 - update to 4.5
SCALANCE XC206-2G PoE - update to 4.5
SCALANCE XC206-2G PoE EEC - update to 4.5
SCALANCE XC206-2SFP - update to 4.5
SCALANCE XC206-2SFP EEC - update to 4.5
SCALANCE XC206-2SFP G - update to 4.5
SCALANCE XC206-2SFP G EEC - update to 4.5
SCALANCE XC208EEC - update to 4.5
SCALANCE XC224-4C G EEC - update to 4.5
SCALANCE XC224 - update to 4.5
SCALANCE XC216EEC - update to 4.5
SCALANCE XC216-4C G EEC - update to 4.5
SCALANCE XC216-4C G - update to 4.5
SCALANCE XC216-4C - update to 4.5
SCALANCE XC216-3G PoE - update to 4.5
SCALANCE XC216 - update to 4.5
SCALANCE XC208G EEC - update to 4.5
SCALANCE XC208G - update to 4.5
SCALANCE XC208 - update to 4.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
EMC ViPR SRM - update to 4.10.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
Events Operator - update to 5.1.0
IBM Spectrum Control - update to 5.4.10.2
RecoverPoint for VMs - update to 6.0.SP1.P1
Storage Ceph - addressed in versions 6.1z1, 7.1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
IBM Safer Payments - addressed in versions 6.3.1.05, 6.4.2.04, 6.5.0.02
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
mysql-server-8.0 (Ubuntu package) - addressed in versions 8.0.35-0ubuntu0.20.04.1, 8.0.35-0ubuntu0.22.04.1, 8.0.35-0ubuntu0.23.04.1, 8.0.35-0ubuntu0.23.10.1
Dell EMC VxRail Appliance - update to 8.0.101
IBM MQ for HPE NonStop - update to 8.1.0.16
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
Index Engines CyberSense - update to 8.3
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
IBM MQ - addressed in versions 9.0.0.19, 9.1.0.17, 9.2.0.16, 9.3.0.10
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
FOS Firmware - addressed in versions 9.1.1d, 9.2.0b, 9.2.1
IBM MQ Appliance - addressed in versions 9.2.0.16, 9.3.0.10, 9.3.3.1
Cisco NX-OS - update to 9.4(1a)
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM DataPower Gateway - addressed in versions 10.0.1.14, 10.5.0.6
IBM Security Verify Access - update to 10.0.7.0
libnode64 (Ubuntu package) - update to 10.19.0~dfsg-3ubuntu1.5
nodejs (Ubuntu package) - addressed in versions 10.19.0~dfsg-3ubuntu1.5, 12.22.9~dfsg-1ubuntu3.4, 18.13.0+dfsg1-1ubuntu2.1
IBM App Connect Enterprise - addressed in versions 11.0.0.22, 12.0.10.0
Cognos Transformer - update to 11.1.7 Fix Pack 8
Event Streams - update to 11.5.1
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
libnode72 (Ubuntu package) - update to 12.22.9~dfsg-1ubuntu3.4
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.24
shim - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debuginfo - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
shim-debugsource - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35
libnode108 (Ubuntu package) - update to 18.13.0+dfsg1-1ubuntu2.1
Dell EMC NetWorker vProxy - addressed in versions 19.8.0.3, 19.9.0.2
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202002-18
edk2-ovmf - update to 202002-18
edk2-aarch64 - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-help - update to 202002-18
edk2-debugsource - update to 202002-18
edk2-devel - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2 (Red Hat package) - update to 20230524-3.el9
Storage Insights - Data Collector - update to 20230809-0820
External References
Related Security Bulletins
- Denial of service in OpenSSL
- Ubuntu update for openssl
- SUSE update for openssl
- SUSE update for openssl-1_0_0
- SUSE update for openssl-1_0_0
- SUSE update for compat-openssl098
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- Slackware Linux update for openssl
- Debian update for openssl
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl1
- SUSE update for openssl
- Amazon Linux AMI update for openssl
- SUSE update for openssl-3
- Red Hat Enterprise Linux 9 update for openssl
- Ubuntu update for openssl
- SUSE update for openssl-1_1
- SUSE update for openssl-3
- F5 BIG-IP update for OpenSSL
- F5 BIG-IQ Centralized Management update for OpenSSL
- F5 Traffix SDC update for OpenSSL
- F5OS update for OpenSSL
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in IBM Watson Explorer
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Tenable Nessus Agent
- Resource management error in IBM DataPower Gateway potentially vulnerable to Denial of Service
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Tenable Security Center update for OpenSSL
- Tenable Security Center 5 update for OpenSSL
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift
- Multiple vulnerabilities in IBM MobileFirst Platform
- Multiple vulnerabilities in Dell Index Engines CyberSense
- Multiple vulnerabilities in Tenable Sensor Proxy
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Oracle Solaris third-party software
- Resource management error in IBM MQ
- Resource management error in IBM MQ Appliance
- Resource management error in IBM MQ
- VMware Tanzu products update for OpenSSL
- Resource management error in IBM Storage Insights - Data Collector
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM MaaS360 Mobile Enterprise Gateway and VPN Module
- Resource management error in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Spectrum Control
- Resource management error in Oracle Essbase
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Ubuntu update for mysql-8.0
- Red Hat Enterprise Linux 9 update for edk2
- Multiple vulnerabilities in Siemens SCALANCE XB-200 / XC-200 / XP-200 / XF-200BA / XR-300WG Family
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in JBoss Enterprise Web Server 5 for RHEL 7, 8, and 9
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- InfoSphere Information Server update for OpenSSL
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Dell Platform BIOS update for OpenSSL
- Gentoo update for OpenSSL
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cognos Transformer
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Ubuntu update for nodejs
- openEuler 22.03 LTS update for shim
- openEuler 22.03 LTS SP1 update for shim
- openEuler 22.03 LTS SP2 update for shim
- openEuler 22.03 LTS SP3 update for shim
- openEuler 20.03 LTS SP1 update for shim
- openEuler update for edk2
- openEuler 20.03 LTS SP4 update for shim
- openEuler 20.03 LTS SP1 update for openssl
- openEuler 20.03 LTS SP3 update for openssl
- openEuler 22.03 LTS update for openssl
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for VMware
- Multiple vulnerabilities in IBM Storage Protect Client
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in IBM Workload Automation
- Resource management error in IBM FOS firmware
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Resource management error in NX-OS Firmware
- Multiple vulnerabilities in IBM Security Verify Access
- Denial of service in Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Aspera Shares
- Multiple vulnerabilities in IBM Cloud Pak System
- IBM InfoSphere Master Data Management update for OpenSSL
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in HPE OneView
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Events Operator
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME firmware (August 2023)
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Cloud Pak for Data System 2.0
- Dell NetWorker update for OpenSSL
- Ubuntu update for edk2
- Ubuntu update for edk2
- Juniper Session Smart Router update for third-party components