QID 330133

Date Published: 2023-03-29

QID 330133: IBM Advanced Interactive eXecutive (AIX) Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (openssl_advisory38)

A vulnerability in OpenSSL cause a denial service (CVE-2022-3996, CVE-2023-0401, CVE-2022-4203, CVE-2023-0216, CVE-2023-0215, CVE-2023-0217, CVE-2023-0286, CVE-2022-4450) or obtain sensitive information (CVE-2022-4304).OpenSSL is used by AIX as part of AIX's secure network communications

Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i openssl.base. It also checks for interim fixes installed The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

A vulnerability in OpenSSL cause denial of service and information disclosure

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    The vendor has released fixes to openssl_advisory38 this vulnerability.
    Software Advisories
    Advisory ID Software Component Link
    openssl_advisory38 URL Logo aix.software.ibm.com/aix/efixes/security/openssl_advisory38.asc