Information is circulating describing a method called "Heartbleed," which exploits a vulnerability caused by a design error in OpenSSL. This technote provides confirmation that IBM Notes and Domino are not susceptible to the Heartbleed attack.
IBM Notes and Domino are not vulnerable to the Heartbleed bug because they do not use OpenSSL as the basis of the SSL stack in the products. Note that this includes both the Domino SSL stack as well as the TLS implementation supported by the IBM HTTP Server in 9.0. Notes Traveler is also not affected.
For more information on the Heartbleed bug, including a Q&A, go to http://www.heartbleed.com.
|Messaging Applications||IBM Notes||9.0, 8.5, 8.0|
|Messaging Applications||IBM Notes Traveler||9.0, 8.5, 8.0.1|