MDM and the "Heartbleed Bug" (CVE-2014-0160)

(imported topic written by rheng)

An OpenSSL vulnerability was announced earlier this week in versions 1.0.1 and 1.0.2 of OpenSSL. This vulnerability is officially named “TLS heartbeat read overrun (CVE-2014-0160)” and has come to be colloquially named “The Heartbleed Bug”.

Mobile Device Management is unaffected .

Official advisory :
http://www.openssl.org/news/secadv_20140407.txt

More details :
http://heartbleed.com

To see updates on how this vulnerability affects IEM applications, click either of the links below:

https://www.ibm.com/developerworks/community/blogs/a1a33778-88b7-452a-9133-c955812f8910/entry/security_bulletin_ibm_endpoint_manager_9_1_1065_openssl_vulnerability_update_cve_2014_0160?lang=en

http://www.ibm.com/support/docview.wss?uid=swg21670161