System Manager: CVE's related to OpenSSL security vulnerabilities


Doc ID    SOLN269459
Version:    3.0
Status:    Published
Published date:    03 Dec 2019
Created Date:    01 Jun 2015
Author:   
Gina Reda
 

Details

System Manager  6.x

CMS R17.X

Problem Clarification

CVE-2014-0224, CVE-2014-0221, CVE-2014-0195, CVE-2014-0198, CVE-2010-5298, CVE-2014-3470, CVE-2014-0076

Cause

Security vulnerabilities

Solution

CVE-2014-0224 ASA-2014-255 openssl security update (RHSA-2014-0624)

https://downloads.avaya.com/css/P8/documents/100181215

Recommendation to Upgrade to 6.3.10 or later.


CVE-2014-0221 ASA-2014-356 openssl security update (RHSA-2014-1053)

https://downloads.avaya.com/css/P8/documents/100005330

Recommendation to Upgrade to 6.3.10 or later.



CVE-2014-0076 ASA-2014-163 VMware product updates address OpenSSL security vulnerabilities

https://downloads.avaya.com/css/P8/documents/100179859

Avaya recommends that customers install the security update as detailed in the VMware security advisory.


All of the following CVE's are part of the same RHSA-2014-0625

https://rhn.redhat.com/errata/RHSA-2014-0625.html


CVE-2014-0195 ASA-2014-235 openssl security update (RHSA-2014-0625)

https://downloads.avaya.com/css/P8/documents/100181099

Recommendation to Upgrade to 6.3.9 or later


CVE-2014-0198 ASA-2014-235 openssl security update (RHSA-2014-0625)

https://downloads.avaya.com/css/P8/documents/100181099

Recommendation to Upgrade to 6.3.9 or later


CVE-2010-5298 ASA-2014-235 openssl security update (RHSA-2014-0625)

https://downloads.avaya.com/css/P8/documents/100181099

Recommendation to Upgrade to 6.3.9 or later



CVE-2014-3470 ASA-2014-235 openssl security update (RHSA-2014-0625)

https://downloads.avaya.com/css/P8/documents/100181099

Recommendation to Upgrade to 6.3.9 or later

 

CMS 

https://downloads.avaya.com/css/P8/documents/101012435

Recommendation to upgrade to R17jd.d or latter

Additional Relevant Phrases

Security Vulnerability

Avaya -- Proprietary. Use pursuant to the terms of your signed agreement or Avaya policy