Is Portal MySql vulnerable to these OpenSSL vulnerabilities?
search cancel

Is Portal MySql vulnerable to these OpenSSL vulnerabilities?

book

Article ID: 278325

calendar_today

Updated On:

Products

DX NetOps CA Performance Management - Usage and Administration

Issue/Introduction

Is the DX NetOps Portal MySql version vulnerable to these vulnerabilities?

Is Portal impacted by these CVE's triggered by internal security scans?

Plug In ID: 184811

PlugIn Name: OpenSSL 1.1.1 < 1.1.1x Vulnerability
PlugIn Text: "Plugin Output:

  Path             : /opt/CAPM/MySql/lib/private/libssl.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1x

  Path             : /opt/CAPM/MySql/lib/private/libcrypto.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1x"

Plug In ID: 178475

Plugin Name: OpenSSL 1.1.1 < 1.1.1v Vulnerability
PlugIn Text:  "Plugin Output: 

  Path             : /opt/CAPM/MySql/lib/private/libssl.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1v

  Path             : /opt/CAPM/MySql/lib/private/libcrypto.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1v"

Plug In ID: 173260

PlugIn Name: OpenSSL 1.1.1 < 1.1.1u Multiple Vulnerabilities
PlugIn Text: "Plugin Output: 

  Path             : /opt/CAPM/MySql/lib/private/libssl.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1u

  Path             : /opt/CAPM/MySql/lib/private/libcrypto.so.1.1
  Reported version : 1.1.1t
  Fixed version    : 1.1.1u

Environment

All supported DX NetOps Portal releases 23.3.2 and earlier

Cause

Plug In ID: 184811 is referring to CVE-2023-5678

Plug In ID: 178475 is referring to CVE-2023-3446

Plug In ID: 173260 is referring to CVE-2023-0464

Resolution

 

To resolve CVE-2023-3446 and CVE-2023-0464

Upgrade to NetOps releases 23.3.3 or newer.

..

CVE-2023-5678 has no ETA at this time.

Dx NetOps 23.3.9 will use MySql 8.0.36 - openssl 3.0.12 libs

 

This is the latest version of mysql available, and the openssl libs are embedded.

As soon as a newer version is available from mysql, Broadcom will include it in a newer build of NetOps.