Inadequate encryption strength in OpenSSH - CVE-2023-48795
Published: December 19, 2023 / Updated: January 31, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to incorrect implementation of the SSH Binary Packet Protocol (BPP), which mishandles the handshake phase and the use of sequence numbers. A remote attacker can perform MitM attack and delete the SSH2_MSG_EXT_INFO message sent before authentication starts, allowing the attacker to disable a subset of the keystroke timing obfuscation features introduced in OpenSSH 9.5.
The vulnerability was dubbed "Terrapin attack" and it affects both client and server implementations.
Affected software
IBM Security Verify Access
IBM Cloud Pak for Data Scheduling
IBM Business Automation Workflow
Red Hat OpenShift Builds
z/Transaction Processing Facility ( z/TPF)
Migration Toolkit for Runtimes
Service Telemetry Framework
IBM Cloud Pak for Data System
Oracle Communications Converged Charging System
Cryostat
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
Red Hat build of Quarkus
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Knowledge Catalog in Cloud Pak for Data
OpenShift Logging
IBM Sterling B2B Integrator
IBM Sterling Partner Engagement Manager
Security Event Manager (SEM)
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle Communications Session Report Manager
Oracle SD-WAN Edge
Oracle Middleware Common Libraries and Tools
Oracle Enterprise Data Quality
Enterprise Manager Base Platform
Oracle Blockchain Platform
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Oracle Communications Cloud Native Core Network Exposure Function
Management Cloud Engine
IBM Concert Software
Multicluster GlobalHub
IBM MQ Operator
IBM Fusion HCI
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Session Smart Router
UCD - IBM UrbanCode Deploy
IBM Tivoli Netcool Impact
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
Azure Stack
OPatchAuto
Red Hat OpenStack
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
IBM Observability with Instana
Aruba CX 4100i Switch Series
RUGGEDCOM APE1808
Aruba CX 10000 Switch Series
Aruba CX 9300 Switch Series
Aruba CX 8400 Switch Series
Aruba CX 8360 Switch Series
Aruba CX 8325 Switch Series
Aruba CX 8320 Switch Series
Aruba CX 6400 Switch Series
Aruba CX 6300 Switch Series
Aruba CX 6200 Switch Series
Aruba CX 6100 Switch Series
Aruba CX 6000 Switch Series
AirWave Management Platform
Gentoo Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
F5OS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Server Module
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM AIX
IBM i
OpenBSD
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
FreeBSD
Slackware Linux
macOS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Desktop Applications Module
Development Tools Module
Server Applications Module
Python 3 Module
openSUSE Leap
Ubuntu
Junos OS
Junos OS Evolved
openEuler
IBM Power 10
Trilead API
OpenShift API for Data Protection (OADP)
libssh
Podman
PuTTY
Migration Toolkit for Containers
OpenShift Serverless Client
IBM Edge Application Manager
Red Hat OpenShift Container Platform
Traffix SDC
JD Edwards EnterpriseOne Tools
OSS Support Tools
IBM i Access Client Solutions
IBM DataPower Gateway
IBM Netezza Analytics
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Supplied MQ Advanced Queue Manager Container images
OpenShift Container Platform for Windows Containers
Terraform
Operations Analytics - Log Analysis
ssh-audit
QRadar App SDK
UCC Edge
DB2 Data Management Console
Oracle Communications Operations Monitor
Storage Ceph
IBM Business Automation Manager Open Editions
webMethods Managed File Transfer
Oracle Data Integrator
Oracle Application Testing Suite
Oracle Communications User Data Repository
Oracle Communications EAGLE Application Processor
Oracle Retail Xstore Point of Service
otp
Db2 Rest
DataPower Operations Dashboard
PowerVault ME5
ObjectScale
IBM i Modernization Engine for Lifecycle Integration
IBM Planning Analytics Workspace
Storage Copy Data Management
Storage Virtualize Ansible Collection
PowerProtect DP Series Appliance (IDPA)
PowerStore X
EMC ECS
Dell EMC PowerStore Family Operating System
PowerStore T
Enterprise SONiC
Storage Resource Manager
SimpliVity Omnistack
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Disk Library for mainframe (DLm)
Storage Protect Server
Storage Virtualize
IBM MQ Appliance
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Container Agent
Storage Protect Plus Server
EMC Cloud Tiering Appliance
CloudBoost Virtual Appliance
watsonx.data
Jenkins
Jenkins LTS
IBM VIOS
JBoss Enterprise Application Platform
Oracle Coherence
Wildfly Core
FileZilla
OpenShift Developer Tools and Services
MySQL Workbench
IBM App Connect Enterprise
Oracle SQL Developer
IBM CICS TX Standard
Oracle Autonomous Health Framework
Oracle Analytics Desktop
IBM Qradar SIEM
LANTIME Operating System Firmware (LTOS)
QuTS hero
Cray XD670
ArubaOS-CX (AOS-CX)
Junos cRPD
Juniper Secure Analytics (JSA)
Splunk Enterprise
MySQL Cluster
RSA Authentication Manager
Oracle Financial Services Compliance Studio
Oracle Communications Element Manager
Oracle SOA Suite
Oracle Global Lifecycle Management NextGen OUI Framework
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dropbear-bin (Ubuntu package)
lxc2 (Ubuntu package)
golang-github-lxc-lxd-dev (Ubuntu package)
lxd-tools (Ubuntu package)
lxd-client (Ubuntu package)
lxd (Ubuntu package)
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
python3-asyncssh (Ubuntu package)
dropbear (Ubuntu package)
eap7-jboss-annotations (Red Hat package)
toolbox
toolbox-tests
toolbox (Red Hat package)
udica
jsch-demo
jsch-javadoc
jsch
rust-bootupd (Red Hat package)
libssh-4 (Ubuntu package)
libssh
libssh-debugsource
libssh-devel
libssh-debuginfo
libssh-help
libssh (Red Hat package)
libssh-config
libssh-doc
libssh (Debian package)
libssh4-32bit
libssh4-debuginfo
libssh4
libssh4-debuginfo-32bit
libssh4-32bit-debuginfo
libssh4-64bit-debuginfo
libssh4-64bit
pam_ssh_agent_auth
net-libs/libssh
golang-x-mod
podman-tui
restic
coreos-installer (Red Hat package)
golang-x-crypto
libfilezilla
putty (Debian package)
putty
net-misc/putty
eap7-jgroups-kubernetes (Red Hat package)
phpseclib (Debian package)
eap7-jboss-cert-helper (Red Hat package)
eap7-insights-java-client (Red Hat package)
eap8-parsson (Red Hat package)
runc (Red Hat package)
runc
age
slirp4netns
oci-seccomp-bpf-hook
rekor-debuginfo
rekor
proftpd-basic (Ubuntu package)
proftpd-core (Ubuntu package)
proftpd
proftpd-debugsource
proftpd-sqlite
proftpd-debuginfo
proftpd-mysql
proftpd-ldap
proftpd-devel
proftpd-utils
proftpd-postgresql
net-ftp/proftpd
eap7-jberet (Red Hat package)
containernetworking-plugins
python3-pynacl
prometheus-podman-exporter
libssh2-devel
libssh2
libssh2-help
libssh2-debuginfo
libssh2-debugsource
eap7-elytron-web (Red Hat package)
aardvark-dns
openshift-serverless-clients (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
netavark
libssh2-1 (Ubuntu package)
libssh2-docs
libssh2-1-debuginfo-32bit
libssh2-1-32bit
libssh2-1-debuginfo
libssh2-1
libssh2_org-debugsource
libssh2-1-32bit-debuginfo
skopeo (Red Hat package)
fuse-overlayfs
crun (Red Hat package)
crun
skopeo-tests
skopeo
gopass-hibp
eap7-wildfly-elytron (Red Hat package)
cri-o-debuginfo
cri-o-debugsource
cri-o
buildah-debugsource
buildah-debuginfo
buildah
cri-o (Red Hat package)
cri-tools (Red Hat package)
buildah (Red Hat package)
buildah-tests
rclone
bouncycastle-javadoc
bouncycastle-pg
bouncycastle-mail
bouncycastle-tls
bouncycastle-jmail
bouncycastle-pkix
bouncycastle-util
bouncycastle
containers-common
doctl
php-phpseclib (Debian package)
conmon (Red Hat package)
conmon
cosign
cosign-debuginfo
eap7-undertow (Red Hat package)
python3-paramiko (Ubuntu package)
oath-toolkit (Red Hat package)
python-paramiko
python-paramiko-help
python3-paramiko
apache-sshd-javadoc
apache-sshd
python-asyncssh (Debian package)
python-paramiko (Red Hat package)
eap8-apache-sshd (Red Hat package)
eap7-apache-sshd (Red Hat package)
python-asyncssh
eap7-activemq-artemis (Red Hat package)
ignition (Red Hat package)
eap8-log4j (Red Hat package)
gh
container-selinux (Red Hat package)
container-selinux
jenkins (Red Hat package)
php-phpseclib3 (Debian package)
eap7-hal-console (Red Hat package)
python-paramiko-doc
python311-paramiko
eap7-apache-cxf (Red Hat package)
etcd
etcdctl
eap7-jboss-xnio-base (Red Hat package)
crit
python3-criu
criu-libs
criu
criu-devel
filezilla (Ubuntu package)
filezilla-common (Ubuntu package)
filezilla
libslirp-devel
libslirp
podman (Red Hat package)
podman
python3-podman
app-containers/podman
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-docker
podman-catatonit
jenkins-2-plugins (Red Hat package)
openshift (Red Hat package)
ose-aws-ecr-image-credential-provider (Red Hat package)
openshift-clients (Red Hat package)
openshift-ansible (Red Hat package)
eap7-jboss-remoting (Red Hat package)
eap7-hibernate (Red Hat package)
rust-afterburn (Red Hat package)
eap7-lucene-solr (Red Hat package)
golang-github-git-5
eap7-eclipse-jgit (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
eap8-eclipse-jgit (Red Hat package)
openssh-debugsource
openssh-helpers
openssh-helpers-debuginfo
openssh-fips
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh-debuginfo
openssh
eap7-wildfly (Red Hat package)
openssh-askpass-gnome-debugsource
openssh (Red Hat package)
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-askpass
eap8-wildfly (Red Hat package)
openssh (Debian package)
openssh-common-debuginfo
openssh-server-debuginfo
openssh-cavs-debuginfo
openssh-common
openssh-clients-debuginfo
eap8-lucene-solr (Red Hat package)
eap7-infinispan (Red Hat package)
ceph (Red Hat package)
erlang-reltool
erlang-dialyzer
erlang-os_mon
erlang-asn1
erlang-erl_docgen
erlang-wx
erlang-debuginfo
erlang-odbc
erlang-eldap
erlang-erl_interface
erlang-debugsource
erlang-crypto
erlang-runtime_tools
erlang-tools
erlang-tftp
erlang-xmerl
erlang-sasl
erlang-jinterface
erlang-syntax_tools
erlang-ftp
erlang-observer
erlang-public_key
erlang-eunit
erlang
erlang-mnesia
erlang-ssl
erlang-megaco
erlang-hipe
erlang-compiler
erlang-erts
erlang-examples
erlang-otp_mibs
erlang-common_test
erlang-inets
erlang-et
erlang-parsetools
erlang-ssh
erlang-debugger
erlang-edoc
erlang-stdlib
erlang-diameter
erlang-kernel
erlang-snmp
erlang-epmd
erlang-et-src
erlang-src
erlang-epmd-debuginfo
erlang-diameter-src
erlang-wx-src
erlang-dialyzer-debuginfo
erlang-debugger-src
erlang-reltool-src
erlang-jinterface-src
erlang-dialyzer-src
erlang-observer-src
erlang-wx-debuginfo
erlang-doc
erlang (Debian package)
apache-parent
cockpit-podman
ostree (Red Hat package)
rpm-ostree (Red Hat package)
PeopleSoft Enterprise PeopleTools
IBM API Connect
IBM Security Guardium
Kaspersky Anti Targeted Attack
Oracle Database Server
Oracle GoldenGate
Oracle NoSQL Database
Oracle Retail Customer Management and Segmentation Foundation
Oracle Communications Cloud Native Core Unified Data Repository
IBM Cloud Pak System
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Red Hat Ceph Storage
Dell Storage Manager
RecoverPoint for VMs
How to mitigate CVE-2023-48795
Trilead API - update to 2.141.v284120fd0c46
libssh - addressed in versions 0.9.8, 0.10.6
PuTTY - update to 0.80
Red Hat OpenShift Serverless - addressed in versions 1.31.1, 1.32.0
Red Hat OpenShift Builds - update to 1.0.1
Terraform - update to 1.7.0
Migration Toolkit for Runtimes - update to 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
Operations Analytics - Log Analysis - update to 1.3.8.3 IF1
ssh-audit - update to 3.1.0
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
OpenShift Serverless Client - update to 1.31.1
watsonx.data - update to 2.0.3
IBM Cloud Pak for Data System - update to 2.0.2.1.IF2
Jenkins - update to 2.452
IBM Cloud Transformation Advisor - update to 3.10.2
QRadar App SDK - update to 2.2.1
UCC Edge - update to 2.3.1
Jenkins LTS - update to 2.440.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.3
FileZilla - update to 3.66.4
DB2 Data Management Console - update to 3.1.13.2
Red Hat build of Quarkus - update to 3.2.10
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.3.5, 4.4.0
Podman - update to 4.8.3
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.12.63, 4.13.45, 4.14.14, 4.14.17, 4.14.31, 4.14.32, 4.14.33, 4.14.34, 4.14.35, 4.14.36, 4.14.39, 4.15.0, 4.15.2, 4.15.3, 4.15.25, 4.15.28, 4.16.0, 4.17.0
Storage Ceph - update to 7.0z2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
Security Event Manager (SEM) - update to 2023.4.1
Red Hat Migration Toolkit for Applications - update to 7.0.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.007
JBoss Enterprise Application Platform - addressed in versions 7.4.16, 8.0.1
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP8 IF03, 7.5.0 UP9 IF02
IBM Qradar SIEM - addressed in versions 7.5.0 Update Pack 8 IF01, 7.5.0 Update Pack 9 IF01
IBM Business Automation Manager Open Editions - update to 8.0.7
MySQL Workbench - update to 8.0.38
MySQL Cluster - update to 8.4.1
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
JD Edwards EnterpriseOne Tools - update to 9.2.9.0
IBM API Connect - update to 10.0.8.2 ifix2
IBM App Connect Enterprise - update to 12.0.12.1
macOS - update to 14.4 23E214
Junos OS - addressed in versions 19.4R3-S13, 20.4R3-S10, 21.4R3-S6, 22.1R3-S5, 22.2R3-S3, 22.4R3-S1, 23.2R2, 23.4R2, 24.1R1
Junos OS Evolved - addressed in versions 19.4R3-S13-EVO, 20.4R3-S10-EVO, 21.4R3-S6-EVO, 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R2-EVO, 24.1R1-EVO
Oracle NoSQL Database - addressed in versions 19.5.42, 20.3.40, 21.2.27, 22.3.46, 23.3.32
Wildfly Core - update to 23.0.1
otp - addressed in versions 22.3.4.27, 23.3.4.20
dropbear-bin (Ubuntu package) - addressed in versions Ubuntu Pro, 2020.81-5ubuntu0.1
lxc2 (Ubuntu package) - update to Ubuntu Pro
golang-github-lxc-lxd-dev (Ubuntu package) - update to Ubuntu Pro
lxd-tools (Ubuntu package) - update to Ubuntu Pro
lxd-client (Ubuntu package) - update to Ubuntu Pro
lxd (Ubuntu package) - update to Ubuntu Pro
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1
openssh-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.10, 1:8.9p1-3ubuntu0.5, 1:9.0p1-1ubuntu8.6, 1:9.3p1-1ubuntu3.1
python3-asyncssh (Ubuntu package) - addressed in versions Ubuntu Pro, 1.12.2-1ubuntu0.1, 2.10.1-2ubuntu0.1
dropbear (Ubuntu package) - addressed in versions Ubuntu Pro, 2020.81-5ubuntu0.1
eap7-jboss-annotations (Red Hat package) - addressed in versions api_1.3_spec-2.0.1-3.Final_redhat_00001.1.el7eap, api_1.3_spec-2.0.1-3.Final_redhat_00001.1.el8eap, api_1.3_spec-2.0.1-3.Final_redhat_00001.1.el9eap
QuTS hero - update to h5.1.5.2647 build 20240118
IBM Power 10 - addressed in versions FW1020.60(1020_118), FW1030.50(1030_082), FW1050.11(1050_070)
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox (Red Hat package) - update to 0.1.2-1.rhaos4.15.el9
udica - update to 0.2.6-21
jsch-demo - update to 0.2.15-150200.11.13.1
jsch-javadoc - update to 0.2.15-150200.11.13.1
jsch - update to 0.2.15-150200.11.13.1
rust-bootupd (Red Hat package) - update to 0.2.17-1.el9
libssh-4 (Ubuntu package) - addressed in versions 0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.4-2ubuntu0.2, 0.10.5-3ubuntu1.1
libssh - addressed in versions 0.9.4-9, 0.9.6-8
libssh-debugsource - addressed in versions 0.9.4-9, 0.9.6-8
libssh-devel - addressed in versions 0.9.4-9, 0.9.6-8
libssh-debuginfo - addressed in versions 0.9.4-9, 0.9.6-8
libssh-help - addressed in versions 0.9.4-9, 0.9.6-8
libssh (Red Hat package) - addressed in versions 0.9.6-4.el8_6, 0.9.6-13.el8_8, 0.9.6-13.el8_9, 0.10.4-9.el9_2
libssh - addressed in versions 0.9.6-11, 0.10.5-3
libssh-devel - addressed in versions 0.9.6-11, 0.10.5-3
libssh-config - addressed in versions 0.9.6-11, 0.10.5-3
libssh-doc - addressed in versions 0.9.6-11, 0.10.5-3
libssh (Debian package) - addressed in versions 0.9.8-0+deb11u1, 0.10.6-0+deb12u1
libssh-config - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4-32bit - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh-devel - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4-debuginfo - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4 - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4-debuginfo-32bit - update to 0.9.8-3.12.2
libssh-debugsource - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4-32bit-debuginfo - addressed in versions 0.9.8-150200.13.3.1, 0.9.8-150400.3.3.1
libssh4-64bit-debuginfo - update to 0.9.8-150400.3.3.1
libssh4-64bit - update to 0.9.8-150400.3.3.1
pam_ssh_agent_auth - update to 0.10.3-7.20.0.4
pam_ssh_agent_auth - addressed in versions 0.10.3-9.29, 0.10.4-4.23, 0.10.4-4.25, 0.10.4-4.26
libssh - update to 0.10.6
net-libs/libssh - update to 0.10.6
libssh - update to 0.10.6-1
libssh - addressed in versions 0.10.6-1.fc38, 0.10.6-1.fc39, 0.10.6-2.fc38
golang-x-mod - addressed in versions 0.14.0-1.el9, 0.14.0-1.fc38, 0.14.0-1.fc39
podman-tui - addressed in versions 0.15.0-1.fc38, 0.15.0-1.fc39, 0.15.0-2.el9
restic - addressed in versions 0.17.0-1.fc41, 0.17.0-1.fc42
coreos-installer (Red Hat package) - update to 0.17.0-3.rhaos4.15.el9
golang-x-crypto - addressed in versions 0.18.0-1.el9, 0.18.0-1.fc38, 0.18.0-1.fc39, 0.18.0-1.fc40
libfilezilla - update to 0.45.0-1.fc38
putty (Debian package) - addressed in versions 0.74-1+deb11u1, 0.78-2+deb12u1
putty - addressed in versions 0.80-1.el8, 0.80-1.el9, 0.80-1.fc38, 0.80-1.fc39
net-misc/putty - update to 0.81
Db2 Rest - update to 1.0.0.304
IBM Concert Software - update to 1.0.1
Multicluster GlobalHub - update to 1.0.2
eap7-jgroups-kubernetes (Red Hat package) - addressed in versions 1.0.17-1.Final_redhat_00001.1.el7eap, 1.0.17-1.Final_redhat_00001.1.el8eap, 1.0.17-1.Final_redhat_00001.1.el9eap
phpseclib (Debian package) - addressed in versions 1.0.19-3+deb11u1, 1.0.20-1+deb12u1
DataPower Operations Dashboard - update to 1.0.20.1
eap7-jboss-cert-helper (Red Hat package) - addressed in versions 1.1.2-1.redhat_00001.1.el7eap, 1.1.2-1.redhat_00001.1.el8eap, 1.1.2-1.redhat_00001.1.el9eap
eap7-insights-java-client (Red Hat package) - addressed in versions 1.1.2-1.redhat_00001.1.el7eap, 1.1.2-1.redhat_00001.1.el8eap, 1.1.2-1.redhat_00001.1.el9eap
eap8-parsson (Red Hat package) - addressed in versions 1.1.5-1.redhat_00001.1.el8eap, 1.1.5-1.redhat_00001.1.el9eap
IBM i Access Client Solutions - update to 1.1.9.5
runc (Red Hat package) - update to 1.1.12-1.rhaos4.15.el9
runc - update to 1.1.12-1.0.1
age - addressed in versions 1.2.0-1.fc41, 1.2.0-1.fc42
PowerVault ME5 - update to 1.2.1.0
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
rekor-debuginfo - update to 1.3.5-150400.4.19.1
rekor - update to 1.3.5-150400.4.19.1
proftpd-basic (Ubuntu package) - addressed in versions 1.3.6c-2ubuntu0.1, 1.3.7c+dfsg-1ubuntu0.1
proftpd-core (Ubuntu package) - addressed in versions 1.3.7c+dfsg-1ubuntu0.1, 1.3.8.b+dfsg-1ubuntu0.1, 1.3.8.b+dfsg-2ubuntu1.24.10.1
proftpd - addressed in versions 1.3.8b-1.el9, 1.3.8b-1.fc38, 1.3.8b-1.fc39
proftpd-debugsource - update to 1.3.8b-2
proftpd-sqlite - update to 1.3.8b-2
proftpd-debuginfo - update to 1.3.8b-2
proftpd - update to 1.3.8b-2
proftpd-mysql - update to 1.3.8b-2
proftpd-ldap - update to 1.3.8b-2
proftpd-devel - update to 1.3.8b-2
proftpd-utils - update to 1.3.8b-2
proftpd-postgresql - update to 1.3.8b-2
net-ftp/proftpd - update to 1.3.8b
proftpd - update to 1.3.8b
eap7-jberet (Red Hat package) - addressed in versions 1.3.9-3.SP3_redhat_00001.1.el7eap, 1.3.9-3.SP3_redhat_00001.1.el8eap, 1.3.9-3.SP3_redhat_00001.1.el9eap
ObjectScale - update to 1.4.0
containernetworking-plugins - update to 1.4.0-2.0.1
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.6
python3-pynacl - update to 1.5.0-1
prometheus-podman-exporter - addressed in versions 1.7.0-1.el9, 1.7.0-1.fc38, 1.7.0-1.fc39
libssh2-devel - update to 1.9.0-8
libssh2 - update to 1.9.0-8
libssh2-help - update to 1.9.0-8
libssh2-debuginfo - update to 1.9.0-8
libssh2-debugsource - update to 1.9.0-8
eap7-elytron-web (Red Hat package) - addressed in versions 1.9.4-1.Final_redhat_00001.1.el7eap, 1.9.4-1.Final_redhat_00001.1.el8eap, 1.9.4-1.Final_redhat_00001.1.el9eap
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
aardvark-dns - update to 1.10.0-2.0.1
openshift-serverless-clients (Red Hat package) - update to 1.10.0-6.el8
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-35.Final_redhat_00034.1.el7eap, 1.10.0-35.Final_redhat_00034.1.el8eap, 1.10.0-35.Final_redhat_00034.1.el9eap
netavark - update to 1.10.3-1.0.1
libssh2-1 (Ubuntu package) - update to 1.11.0-2ubuntu0.1
libssh2 - update to 1.11.0-3
libssh2-docs - update to 1.11.0-3
libssh2-devel - update to 1.11.0-3
libssh2-1-debuginfo-32bit - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1
libssh2-1-32bit - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1, 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2-1-debuginfo - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1, 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2-1 - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1, 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2-devel - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1, 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2_org-debugsource - addressed in versions 1.11.0-29.9.1, 1.11.0-29.12.1, 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2-1-32bit-debuginfo - addressed in versions 1.11.0-150000.4.22.1, 1.11.0-150000.4.25.1
libssh2 - update to 1.11.1
libssh2 - addressed in versions 1.11.1-1.el9, 1.11.1-1.el10_0, 1.11.1-1.el10_1, 1.11.1-1.fc40, 1.11.1-1.fc41
skopeo (Red Hat package) - update to 1.11.2-21.1.rhaos4.15.el9
fuse-overlayfs - update to 1.13-1.0.1
crun (Red Hat package) - update to 1.14-1.rhaos4.15.el9
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
gopass-hibp - update to 1.15.13-1.fc41
eap7-wildfly-elytron (Red Hat package) - addressed in versions 1.15.22-1.Final_redhat_00001.1.el7eap, 1.15.22-1.Final_redhat_00001.1.el8eap, 1.15.22-1.Final_redhat_00001.1.el9eap
Cray XD670 - update to 1.19
cri-o-debuginfo - update to 1.23.2-11
cri-o-debugsource - update to 1.23.2-11
cri-o - update to 1.23.2-11
buildah-debugsource - update to 1.26.1-4
buildah-debuginfo - update to 1.26.1-4
buildah - update to 1.26.1-4
cri-o (Red Hat package) - addressed in versions 1.27.7-4.rhaos4.14.gitceaac6e.el8, 1.27.7-4.rhaos4.14.gitceaac6e.el9, 1.28.3-14.rhaos4.15.git33aabd8.el9
cri-tools (Red Hat package) - update to 1.28.0-3.el9
buildah (Red Hat package) - addressed in versions 1.29.1-20.2.rhaos4.15.el9, 1.31.4-1.el9_3
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
rclone - addressed in versions 1.67.0-1.fc41, 1.70.3-1.el9
bouncycastle-javadoc - update to 1.77-150200.3.24.1
bouncycastle-pg - update to 1.77-150200.3.24.1
bouncycastle-mail - update to 1.77-150200.3.24.1
bouncycastle-tls - update to 1.77-150200.3.24.1
bouncycastle-jmail - update to 1.77-150200.3.24.1
bouncycastle-pkix - update to 1.77-150200.3.24.1
bouncycastle-util - update to 1.77-150200.3.24.1
bouncycastle - update to 1.77-150200.3.24.1
containers-common - update to 1-81.0.1
doctl - update to 1.102.0-3.fc40
IBM MQ Operator - addressed in versions 2.0.20, 3.1.1
php-phpseclib (Debian package) - addressed in versions 2.0.30-2+deb11u1, 2.0.42-1+deb12u1
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
conmon (Red Hat package) - update to 2.1.7-1.2.rhaos4.14.el9
conmon - update to 2.1.10-1
cosign - update to 2.2.3-150400.3.17.1
cosign-debuginfo - update to 2.2.3-150400.3.17.1
Storage Copy Data Management - update to 2.2.23.1
eap7-undertow (Red Hat package) - addressed in versions 2.2.30-1.SP1_redhat_00001.1.el7eap, 2.2.30-1.SP1_redhat_00001.1.el8eap, 2.2.30-1.SP1_redhat_00001.1.el9eap
Storage Virtualize Ansible Collection - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
python3-paramiko (Ubuntu package) - addressed in versions 2.6.0-2ubuntu0.3, 2.9.3-0ubuntu1.2, 2.12.0-2ubuntu1.23.10.2
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
python-paramiko - update to 2.7.2-3
python-paramiko-help - update to 2.7.2-3
python3-paramiko - update to 2.7.2-3
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
IBM Fusion HCI - update to 2.8.0
apache-sshd-javadoc - update to 2.9.2-3
apache-sshd - update to 2.9.2-3
python-asyncssh (Debian package) - update to 2.10.1-2+deb12u1
python-paramiko (Red Hat package) - addressed in versions 2.11.0-2.el8ost, 2.11.0-2.el9ost
eap8-apache-sshd (Red Hat package) - addressed in versions 2.12.0-1.redhat_00001.1.el8eap, 2.12.0-1.redhat_00001.1.el9eap
python-paramiko - addressed in versions 2.12.0-2.el8, 2.12.0-2.el9, 3.4.0-1.fc38
apache-sshd - update to 2.12.0-150200.5.8.1
apache-sshd-javadoc - update to 2.12.0-150200.5.8.1
eap7-apache-sshd (Red Hat package) - addressed in versions 2.12.1-1.redhat_00001.1.el7eap, 2.12.1-1.redhat_00001.1.el8eap, 2.12.1-1.redhat_00001.1.el9eap
python-asyncssh - addressed in versions 2.13.2-5.el9, 2.14.2-1.fc39, 2.14.2-1.fc40
eap7-activemq-artemis (Red Hat package) - addressed in versions 2.16.0-18.redhat_00052.1.el7eap, 2.16.0-18.redhat_00052.1.el8eap, 2.16.0-18.redhat_00052.1.el9eap
ignition (Red Hat package) - update to 2.16.2-2.rhaos4.15.el9
eap8-log4j (Red Hat package) - addressed in versions 2.19.0-2.redhat_00001.1.el8eap, 2.19.0-2.redhat_00001.1.el9eap
gh - update to 2.41.0-1.fc40
container-selinux (Red Hat package) - update to 2.228.1-1.rhaos4.15.el9
container-selinux - update to 2.229.0-2
jenkins (Red Hat package) - addressed in versions 2.440.3.1716387933-3.el8, 2.440.3.1716445150-3.el8, 2.440.3.1716445200-3.el8
php-phpseclib3 (Debian package) - update to 3.0.19-1+deb12u2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
PowerStore X - update to 3.2.1.4-2386214
eap7-hal-console (Red Hat package) - addressed in versions 3.3.21-1.Final_redhat_00001.1.el7eap, 3.3.21-1.Final_redhat_00001.1.el8eap, 3.3.21-1.Final_redhat_00001.1.el9eap
python3-paramiko - update to 3.4.0-1
python-paramiko-doc - update to 3.4.0-1
python-paramiko-doc - update to 3.4.0-150400.13.6.1
python311-paramiko - update to 3.4.0-150400.13.6.1
eap7-apache-cxf (Red Hat package) - addressed in versions 3.4.10-2.redhat_00001.1.el7eap, 3.4.10-2.redhat_00001.1.el8eap, 3.4.10-2.redhat_00001.1.el9eap
etcd - update to 3.5.12-150000.7.6.1
etcdctl - update to 3.5.12-150000.7.6.1
EMC ECS - update to 3.8.1.1
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.12-1.SP2_redhat_00001.1.el7eap, 3.8.12-1.SP2_redhat_00001.1.el8eap, 3.8.12-1.SP2_redhat_00001.1.el9eap
Red Hat OpenShift Dev Spaces - update to 3.15.0
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
filezilla (Ubuntu package) - addressed in versions 3.46.3-1ubuntu0.1, 3.58.0-1ubuntu0.1, 3.65.0-3ubuntu0.1
filezilla-common (Ubuntu package) - addressed in versions 3.46.3-1ubuntu0.1, 3.58.0-1ubuntu0.1, 3.65.0-3ubuntu0.1
filezilla - addressed in versions 3.66.4-1.fc38, 3.66.4-1.fc39
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.0, 4.15.14
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
PowerStore T - update to 4.0.0.2-2365061
Enterprise SONiC - update to 4.2.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
podman (Red Hat package) - addressed in versions 4.4.1-14.4.rhaos4.14.el8, 4.4.1-14.4.rhaos4.14.el9, 4.4.1-21.rhaos4.15.el9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
podman - addressed in versions 4.8.3-1.fc38, 4.8.3-1.fc39
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
python3-podman - update to 4.9.0-1
app-containers/podman - update to 4.9.4
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
jenkins-2-plugins (Red Hat package) - addressed in versions 4.12.1716445211-1.el8, 4.13.1716445207-1.el8, 4.14.1716388016-1.el8
openshift (Red Hat package) - addressed in versions 4.14.0-202406060308.p0.g7852426.assembly.stream.el8, 4.14.0-202406060308.p0.g7852426.assembly.stream.el9, 4.15.0-202402142009.p0.g6216ea1.assembly.stream.el9
ose-aws-ecr-image-credential-provider (Red Hat package) - update to 4.15.0-202401231232.p0.gba252ab.assembly.stream.el9
openshift-clients (Red Hat package) - update to 4.15.0-202402070507.p0.g48dcf59.assembly.stream.el9
openshift-ansible (Red Hat package) - update to 4.15.0-202402162207.p0.g1c9b99e.assembly.stream.el9
SimpliVity Omnistack - update to 5.0.0
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
eap7-jboss-remoting (Red Hat package) - addressed in versions 5.0.27-4.SP2_redhat_00001.1.el7eap, 5.0.27-4.SP2_redhat_00001.1.el8eap, 5.0.27-4.SP2_redhat_00001.1.el9eap
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
QNAP QTS - update to 5.1.5.2645 20240116
eap7-hibernate (Red Hat package) - addressed in versions 5.3.36-1.Final_redhat_00001.1.el7eap, 5.3.36-1.Final_redhat_00001.1.el8eap, 5.3.36-1.Final_redhat_00001.1.el9eap
rust-afterburn (Red Hat package) - update to 5.4.3-2.rhaos4.15.el9
Disk Library for mainframe (DLm) - update to 5.5.0.5
eap7-lucene-solr (Red Hat package) - addressed in versions 5.5.5-6.redhat_2.1.el7eap, 5.5.5-6.redhat_2.1.el8eap, 5.5.5-6.redhat_2.1.el9eap
golang-github-git-5 - update to 5.12.0-1.fc41
eap7-eclipse-jgit (Red Hat package) - addressed in versions 5.13.3.202401111512-1.r_redhat_00001.1.el7eap, 5.13.3.202401111512-1.r_redhat_00001.1.el8eap, 5.13.3.202401111512-1.r_redhat_00001.1.el9eap
kernel (Red Hat package) - update to 5.14.0-284.54.1.el9_2
kernel-rt (Red Hat package) - update to 5.14.0-284.54.1.rt14.339.el9_2
RecoverPoint for VMs - update to 6.0.SP1.P1
Kaspersky Anti Targeted Attack - update to 6.0.1 Patch A
Session Smart Router - addressed in versions 6.2.10, 6.3.7
eap8-eclipse-jgit (Red Hat package) - addressed in versions 6.6.1.202309021850-1.r_redhat_00001.1.el8eap, 6.6.1.202309021850-1.r_redhat_00001.1.el9eap
UCD - IBM UrbanCode Deploy - addressed in versions 7.0.5.21, 7.1.2.17, 7.2.3.10, 7.3.2.5, 8.0.1.0
Red Hat Ceph Storage - update to 7.1
IBM Tivoli Netcool Impact - update to 7.1.0.33
openssh-debugsource - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-helpers - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-fips - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-askpass-gnome - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh-debuginfo - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh - addressed in versions 7.2p2-81.8.1, 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
eap7-wildfly (Red Hat package) - addressed in versions 7.4.15-6.GA_redhat_00003.1.el7eap, 7.4.15-6.GA_redhat_00003.1.el8eap, 7.4.15-6.GA_redhat_00003.1.el9eap, 7.4.16-4.GA_redhat_00002.1.el7eap, 7.4.16-4.GA_redhat_00002.1.el8eap, 7.4.16-4.GA_redhat_00002.1.el9eap
openssh-askpass-gnome-debugsource - addressed in versions 7.9p1-150100.6.34.1, 8.1p1-150200.5.43.1, 8.4p1-150300.3.27.1
openssh (Red Hat package) - addressed in versions 8.0p1-19.el8_9.2, 8.7p1-34.el9_3.3
openssh - update to 8.0p1-20.0.4
openssh-server - update to 8.0p1-20.0.4
openssh-ldap - update to 8.0p1-20.0.4
openssh-keycat - update to 8.0p1-20.0.4
openssh-clients - update to 8.0p1-20.0.4
openssh-cavs - update to 8.0p1-20.0.4
openssh-askpass - update to 8.0p1-20.0.4
eap8-wildfly (Red Hat package) - addressed in versions 8.0.1-3.GA_redhat_00002.1.el8eap, 8.0.1-3.GA_redhat_00002.1.el9eap
Storage Protect Server - update to 8.1.23
AirWave Management Platform - update to 8.3.0.3
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
openssh-server - update to 8.4p1-150300.3.27.1
openssh-clients - update to 8.4p1-150300.3.27.1
openssh-common-debuginfo - update to 8.4p1-150300.3.27.1
openssh-server-debuginfo - update to 8.4p1-150300.3.27.1
openssh-cavs-debuginfo - update to 8.4p1-150300.3.27.1
openssh-common - update to 8.4p1-150300.3.27.1
openssh-clients-debuginfo - update to 8.4p1-150300.3.27.1
openssh-cavs - update to 8.4p1-150300.3.27.1
Storage Virtualize - addressed in versions 8.4.0.13, 8.5.0.12, 8.6.0.3, 8.6.2.1, 8.6.3.0, 8.7.0.0
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1, 8.7 SP2 Patch 2
IBM Integrated Analytics System - update to 8.8.24.10.SP1
eap8-lucene-solr (Red Hat package) - addressed in versions 8.11.2-2.redhat_00001.1.el8eap, 8.11.2-2.redhat_00001.1.el9eap
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r2, 9.3.5.0-r2
IBM MQ Appliance - addressed in versions 9.3.0.20, 9.3.5.2
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
IBM DataPower Gateway - addressed in versions 10.0.1.19, 10.5.0.11, 10.5.4
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Security Verify Access - update to 10.0.9
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1
ArubaOS-CX (AOS-CX) - addressed in versions 10.10.1110, 10.12.1030, 10.13.1010
OpenShift Container Platform for Windows Containers - update to 10.15.0
Azure Stack - update to 10.2402
eap7-infinispan (Red Hat package) - addressed in versions 11.0.18-2.Final_redhat_00001.1.el7eap, 11.0.18-2.Final_redhat_00001.1.el8eap, 11.0.18-2.Final_redhat_00001.1.el9eap
IBM CICS TX Standard - update to 11.1.0.0 ifix18
IBM Netezza Analytics - update to 11.2.29
OPatchAuto - update to 12.2.0.1.42
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Red Hat OpenStack - addressed in versions 16.2, 17.1
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp
CloudBoost Virtual Appliance - update to 19.11.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
erlang-reltool - update to 21.3.3-4
erlang-dialyzer - update to 21.3.3-4
erlang-os_mon - update to 21.3.3-4
erlang-asn1 - update to 21.3.3-4
erlang-erl_docgen - update to 21.3.3-4
erlang-wx - update to 21.3.3-4
erlang-debuginfo - update to 21.3.3-4
erlang-odbc - update to 21.3.3-4
erlang-eldap - update to 21.3.3-4
erlang-erl_interface - update to 21.3.3-4
erlang-debugsource - update to 21.3.3-4
erlang-crypto - update to 21.3.3-4
erlang-runtime_tools - update to 21.3.3-4
erlang-tools - update to 21.3.3-4
erlang-tftp - update to 21.3.3-4
erlang-xmerl - update to 21.3.3-4
erlang-sasl - update to 21.3.3-4
erlang-jinterface - update to 21.3.3-4
erlang-syntax_tools - update to 21.3.3-4
erlang-ftp - update to 21.3.3-4
erlang-observer - update to 21.3.3-4
erlang-public_key - update to 21.3.3-4
erlang-eunit - update to 21.3.3-4
erlang - update to 21.3.3-4
erlang-mnesia - update to 21.3.3-4
erlang-ssl - update to 21.3.3-4
erlang-megaco - update to 21.3.3-4
erlang-hipe - update to 21.3.3-4
erlang-compiler - update to 21.3.3-4
erlang-erts - update to 21.3.3-4
erlang-examples - update to 21.3.3-4
erlang-otp_mibs - update to 21.3.3-4
erlang-common_test - update to 21.3.3-4
erlang-inets - update to 21.3.3-4
erlang-et - update to 21.3.3-4
erlang-parsetools - update to 21.3.3-4
erlang-ssh - update to 21.3.3-4
erlang-debugger - update to 21.3.3-4
erlang-edoc - update to 21.3.3-4
erlang-stdlib - update to 21.3.3-4
erlang-diameter - update to 21.3.3-4
erlang-kernel - update to 21.3.3-4
erlang-snmp - update to 21.3.3-4
erlang-epmd - update to 23.3.4.19-150300.3.14.1
erlang-et-src - update to 23.3.4.19-150300.3.14.1
erlang - update to 23.3.4.19-150300.3.14.1
erlang-src - update to 23.3.4.19-150300.3.14.1
erlang-diameter - update to 23.3.4.19-150300.3.14.1
erlang-epmd-debuginfo - update to 23.3.4.19-150300.3.14.1
erlang-debugger - update to 23.3.4.19-150300.3.14.1
erlang-diameter-src - update to 23.3.4.19-150300.3.14.1
erlang-debugsource - update to 23.3.4.19-150300.3.14.1
erlang-reltool - update to 23.3.4.19-150300.3.14.1
erlang-dialyzer - update to 23.3.4.19-150300.3.14.1
erlang-observer - update to 23.3.4.19-150300.3.14.1
erlang-wx-src - update to 23.3.4.19-150300.3.14.1
erlang-wx - update to 23.3.4.19-150300.3.14.1
erlang-dialyzer-debuginfo - update to 23.3.4.19-150300.3.14.1
erlang-debuginfo - update to 23.3.4.19-150300.3.14.1
erlang-debugger-src - update to 23.3.4.19-150300.3.14.1
erlang-reltool-src - update to 23.3.4.19-150300.3.14.1
erlang-jinterface-src - update to 23.3.4.19-150300.3.14.1
erlang-et - update to 23.3.4.19-150300.3.14.1
erlang-dialyzer-src - update to 23.3.4.19-150300.3.14.1
erlang-observer-src - update to 23.3.4.19-150300.3.14.1
erlang-wx-debuginfo - update to 23.3.4.19-150300.3.14.1
erlang-jinterface - update to 23.3.4.19-150300.3.14.1
erlang-doc - update to 23.3.4.19-150300.3.14.1
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1
Oracle Autonomous Health Framework - update to 24.2.0
erlang (Debian package) - update to 1:25.2.3+dfsg-1+deb12u1
apache-parent - update to 31-150200.3.12.1
cockpit-podman - update to 84.1-1
IBM Observability with Instana - update to 272
Dell Storage Manager - update to 2020 R1.21
ostree (Red Hat package) - update to 2023.8-3.el9
rpm-ostree (Red Hat package) - update to 2024.2-1.el9
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in OpenSSH
- Multiple vulnerabilities in libssh
- PuTTY update for OpenSSH
- Fedora 39 update for libssh
- Fedora 38 update for libssh
- OpenBSD update for OpenSSH
- Ubuntu update for libssh
- Ubuntu update for openssh
- Slackware Linux update for libssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- Fedora 39 update for podman-tui
- Fedora EPEL 9 update for podman-tui
- Fedora 38 update for podman-tui
- FreeBSD update for OpenSSH
- Slackware Linux update for proftpd
- Fedora 38 update for proftpd
- Fedora 39 update for proftpd
- FileZilla Client update for Terrapin protocol vulerability
- Fedora 39 update for filezilla
- Fedora 38 update for filezilla, libfilezilla
- SUSE update for libssh2_org
- Fedora 40 update for python-asyncssh
- Fedora 39 update for python-asyncssh
- Fedora EPEL 9 update for proftpd
- ssh-audit update for Terrapin protocol vulerability
- Fedora 38 update for libssh
- Debian update for putty
- Debian update for openssh
- Gentoo update for OpenSSH
- Gentoo update for libssh
- Fedora 40 update for doctl
- SUSE update for libssh2_org
- Fedora 38 update for python-paramiko
- Fedora EPEL 9 update for python-paramiko
- Fedora 39 update for putty
- Fedora 38 update for putty
- Fedora EPEL 9 update for putty
- Fedora EPEL 8 update for putty
- Fedora EPEL 8 update for python-paramiko
- Fedora 39 update for podman
- Fedora 38 update for podman
- Inadequate encryption strength in Podman
- SUSE update for python-paramiko
- Fedora 40 update for gh
- Fedora 40 update for golang-x-crypto
- Fedora 39 update for golang-x-crypto
- Fedora 38 update for golang-x-crypto
- Fedora EPEL 9 update for golang-x-crypto
- Fedora 38 update for golang-x-mod
- Fedora EPEL 9 update for golang-x-mod
- Fedora 39 update for golang-x-mod
- Ubuntu update for openssh
- Ubuntu update for libssh2
- Inadequate encryption strength in Terraform
- SUSE update for libssh
- Ubuntu update for filezilla
- Fedora EPEL 9 update for prometheus-podman-exporter
- Fedora 38 update for prometheus-podman-exporter
- Fedora 39 update for prometheus-podman-exporter
- Wildfly Core update for OpenSSH
- SUSE update for erlang
- SUSE update for apache-parent, apache-sshd
- Ubuntu update for paramiko
- Red Hat Enterprise Linux 9.2 Extended Update Support update for libssh
- Terrapin SSH attack in Junos OS and Junos OS Evolved
- Red Hat Enterprise Linux 8.6 Extended Update Support update for libssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 8.8 Extended Update Support update for libssh
- Red Hat Enterprise Linux 8 update for libssh
- Multiple vulnerabilities in IBM Edge Application Manager
- Inadequate Encryption Strength in QNAP QTS and QuTS hero
- SUSE update for bouncycastle, jsch
- SUSE update for cosign
- Multiple vulnerabilities in Red Hat build of Quarkus
- Multiple vulnerabilities in Red Hat build of Quarkus 3.2
- SUSE update for rekor
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- SUSE update for libssh
- SUSE update for libssh2_org
- SUSE update for libssh2_org
- SUSE update for libssh
- Multiple vulnerabilities in Red Hat OpenShift Serverless Client
- Kaspersky Anti Targeted Attack update for OpenSSH
- Inadequate encryption strength in IBM i
- Multiple vulnerabilities in Red Hat Multicluster GlobalHub
- Multiple vulnerabilities in Red Hat Openshift distributed tracing
- Multiple vulnerabilities in IBM VIOS and IBM AIX
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Inadequate encryption strength in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- SolarWinds Security Event Manager (SEM) update for third-party components
- Multiple vulnerabilities in Apple macOS Sonoma
- Inadequate encryption strength in Jenkins Trilead API plugin
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- openEuler 22.03 LTS SP1 update for libssh
- Inadequate encryption strength in IBM Datapower Operations Dashboard
- Multiple vulnerabilities in IBM i Modernization Engine for Lifecycle Integration
- openEuler 22.03 LTS update for openssh
- openEuler 22.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP2 update for openssh
- openEuler 20.03 LTS SP1 update for libssh
- openEuler 22.03 LTS update for libssh
- openEuler 20.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP3 update for openssh
- openEuler update for python-paramiko
- openEuler 22.03 LTS SP3 update for libssh
- openEuler update for apache-sshd
- openEuler 22.03 LTS SP2 update for libssh
- openEuler update for erlang
- Red Hat Enterprise Linux 9 update for openssh
- Red Hat Enterprise Linux 9 update for buildah
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Red Hat JBoss Enterprise Application Platform 7.4 update for ssh
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 8.0
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 8.0
- Inadequate encryption strength in OTP
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Inadequate encryption strength in IBM Business Automation Workflow
- openEuler 20.03 LTS SP4 update for libssh
- openEuler 20.03 LTS SP4 update for openssh
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- openEuler update for proftpd
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Logging Subsystem 5.8 for Red Hat OpenShift for RHEL 9
- Inadequate encryption strength in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 7
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM QRadar App SDK
- Inadequate encryption strength in IBM Cloud Pak for Data Scheduling
- Multiple vulnerabilities in IBM QRadar SIEM
- Inadequate encryption strength in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)
- openEuler 22.03 LTS SP1 update for cri-o
- openEuler 22.03 LTS SP2 update for cri-o
- openEuler 22.03 LTS SP3 update for cri-o
- Multiple vulnerabilities in Siemens RUGGEDCOM APE1808
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Inadequate encryption strength in Oracle Autonomous Health Framework
- Multiple vulnerabilities in Oracle Database Server
- Inadequate encryption strength in OPatchAuto
- Multiple vulnerabilities in Oracle Communications User Data Repository
- Multiple vulnerabilities in Oracle Communications Session Report Manager
- Multiple vulnerabilities in Oracle Communications Element Manager
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Inadequate encryption strength in Oracle Global Lifecycle Management NextGen OUI Framework
- Inadequate encryption strength in Oracle Coherence
- Multiple vulnerabilities in Oracle SOA Suite
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- Multiple vulnerabilities in OSS Support Tools
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Inadequate encryption strength in Jenkins and Jenkins LTS
- Inadequate encryption strength in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Ubuntu update for lxd
- Fedora 41 update for golang-github-git-5
- openEuler update for libssh2
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Multiple vulnerabilities in IBM Storage Copy Data Management
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Storage Fusion HCI
- Inadequate encryption strength in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Inadequate encryption strength in IBM App Connect Enterprise
- Terrapin attack in Aruba AOS-CX switches
- Inadequate encryption strength in IBM Watson Discovery for IBM Cloud Pak for Data
- Inadequate encryption strength in IBM i Access Client Solutions
- Red Hat Product OCP Tools 4.14. Red Hat Product Security has rated this update as having a security impact of Important update for Openshift Jenkins
- Red Hat Product OCP Tools 4.12. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Product OCP Tools 4.13. Red Hat Product Security has rated this update as having a security impact of Important update for OpenShift Jenkins
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Inadequate encryption strength in Red Hat OpenStack 17 packages
- Inadequate encryption strength in Red Hat OpenStack 17 packages
- Inadequate encryption strength in Red Hat OpenShift Container Platform 4.14 packages
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Disk Library for mainframe
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Inadequate encryption strength in IBM MQ Appliance
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Inadequate encryption strength in IBM Storage Protect Server
- Gentoo update for PuTTY
- Gentoo update for podman
- Inadequate encryption strength in IBM Storage Virtualize Ansible Collection
- Fedora 41 update for gopass-hibp
- Multiple vulnerabilities in IBM Observability with Instana
- Debian update for phpseclib
- Debian update for php-phpseclib
- Debian update for php-phpseclib3
- Debian update for libssh
- Inadequate encryption strength in Oracle NoSQL Database
- Inadequate encryption strength in Oracle GoldenGate
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Converged Charging System
- Multiple vulnerabilities in Oracle Analytics Desktop
- Inadequate encryption strength in Oracle Enterprise Data Quality
- Multiple vulnerabilities in Oracle Data Integrator
- Inadequate encryption strength in Oracle Application Testing Suite
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in MySQL Cluster
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Dell UCC Edge
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Dell PowerVault ME5
- Multiple vulnerabilities in Dell CloudBoost Virtual Appliance
- Amazon Linux AMI update for libssh
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Dell ObjectScale
- Fedora 41 update for rclone
- Inadequate encryption strength in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- Fedora 42 update for age
- Fedora 41 update for age
- Fedora 42 update for restic
- Fedora 41 update for restic
- Debian update for python-asyncssh
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Security Guardium
- Inadequate encryption strength in IBM Power 10
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Total Storage Service Console (TSSC) / TS4500 IMC
- Inadequate encryption strength in Storage Virtualize
- Multiple vulnerabilities in IBM Concert
- HPE Aruba AirWave Management Platform update for OpenSSH
- MitM attack in F5OS OpenSSH component
- MitM attack in F5 Traffix SDC OpenSSH component
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Ubuntu update for python-asyncssh
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Oracle Blockchain Platform
- Inadequate encryption strength in Oracle Communications EAGLE Application Processor
- Multiple vulnerabilities in Management Cloud Engine
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Inadequate encryption strength in Oracle SQL Developer
- SUSE update for etcd
- Slackware Linux update for libssh2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- IBM Integrated Analytics System update for OpenSSH
- IBM Sterling B2B Integrator update for OpenSSH
- Multiple vulnerabilities in Dell PowerStore T Family
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- openEuler 22.03 LTS SP4 update for buildah
- Multiple vulnerabilities in Dell PowerProtect DP Series Appliance (IDPA)
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Oracle Financial Services Compliance Studio
- Multiple vulnerabilities in IBM Security Verify Access
- IBM watsonx.data update for OpenSSH
- Amazon Linux AMI update for openssh
- IBM z/Transaction Processing Facility update for Apache Mina SSHD package
- Ubuntu update for dropbear
- Ubuntu update for proftpd-dfsg
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for SSH Binary Packet Protocol (BPP)
- Fedora 41 update for libssh2
- Fedora 40 update for libssh2
- Fedora EPEL 10.1 update for libssh2
- Fedora EPEL 10.0 update for libssh2
- IBM Cloud Pak for Data System 2.0 update for paramiko
- Anolis OS update for python-pynacl
- Anolis OS update for libssh
- Anolis OS update for libssh
- Anolis OS update for container-tools:an8 module
- Anolis OS update for openssh
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Inadequate encryption strength in HPE SimpliVity Servers Using SSH
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Debian update for erlang
- Fedora EPEL 9 update for python-asyncssh
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- RSA Authentication Manager update for third-party components
- RSA Authentication Manager update for third-party components
- Meinberg LANTIME firmware update for third-party components (January 2024)
- Multiple vulnerabilities in Dell Storage Manager
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in HPE Cray XD670
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Netezza Analytics - NPS
- Fedora EPEL 9 update for rclone
- Anolis OS update for python-paramiko and libssh2
- Gentoo update for ProFTPd
- Fedora EPEL 9 update for libssh2
- IBM Storage Ceph update for python-asyncssh
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- IBM Operations Analytics - Log Analysis update for OpenSSH
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Juniper Session Smart Router update for third-party components