Remediation for CVE‑2023‑0286
search cancel

Remediation for CVE‑2023‑0286

book

Article ID: 445723

calendar_today

Updated On:

Products

CA Harvest Software Change Manager CA Harvest Software Change Manager - OpenMake Meister

Issue/Introduction

Do you have OpenSSL Vulnerability Remediation information for CVE-2023-0286?

Environment

CA Harvest Software Change Manager (SCM) 14.0, 14.5, 14.5.01

Cause

OpenSSL vulnerability CVE-2023-0286 affects versions of CA Harvest SCM utilizing CAPKI 5.2.6.

Resolution

Identify the installed version of CA Harvest Software Change Manager to determine vulnerability status:

  • Harvest v14.5 and v14.5.01: These versions utilize OpenSSL 3.0.8 and 3.4.0, respectively. These versions are not vulnerable to CVE-2023-0286.
  • Harvest v14.0.x: This version utilizes CAPKI 5.2.6, which is confirmed to be vulnerable.  If this is your version of Harvest we recommend to upgrade as soon as possible.

Additional Information

Information about upgrading Harvest to v14.5.0 and 14.5.01 can be found here:

CA Harvest SCM 14.5 Upgrading

Install CA Harvest SCM Cumulative Patch V14.5.01 on Linux and Unix (version: 14.5)

Install CA Harvest SCM Cumulative Patch V14.5.01 on Windows (version: 14.5)

CA Harvest SCM Upgrade and Hot Site Preparation