Still working on the list...
You can sign up for IBM Notifications at:
https://www-947.ibm.com/systems/support/myview/subscription/css.wss/
You can even limit that down to IBM i 7.1, Security Notifications.
You can search APARs for CVE at
http://www-912.ibm.com/n_dir/nas4apar.nsf/$$Search?openform
If I limit that search down to IBM i 7.1 I get 20 hits
                APAR            Status  Abstract 
97%             SE64529 CLOSED PER      SC1-UTL OPENSSH PATCH SECURITY 
VULNERABILITIES 
97%             SE58711 CLOSED PER      HTTPSVR - Security Patch for 
CVE-2014-0098 
97%             SE55234 CLOSED PER      F/DG1 VULNERABILITIES-MSGAUDIT 
REPORT CVE 2012-3499 / CVE 
97%             SE48199 CLOSED PER      HTTPSVR - Patch Apache 
Vulnerability CVE-2011-0419 and 
96%             SE45583 CLOSED PER      HTTPSVR - FastCGI socket 
authorities directives support 
96%             SE44955 CLOSED PER      HTTPSVR - Patch Apache 
Vulnerability CVE-2010-1623 
95%             SE65372 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2016-0718 
95%             SE65321 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2016-5387 
95%             SE61067 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2013-5704 
95%             SE59706 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2014-0118 
95%             SE53910 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITYS CVE-2012-2687 
95%             SE51504 CLOSED PER      HTTPSVR - Follow up fix for 
CVE-2011-4317 
95%             SE49722 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2011-3368 
95%             SE49333 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2011-3192 
94%             SE58603 CLOSED PER      HTTPSVR - HTTP SERVER FOR I 2.4 
SUPPORT 
92%             SE44232 CLOSED PER      HTTPSVR - PATCH APACHE 
VULNERABILITY CVE-2010-2068 
92%             SE42388 CLOSED PER      HTTPSVR - Patch Apache 
Vulnerability CVE 2010 0434 
90%             SE39535 CLOSED PER      HTTPSVR - Patch Apache 
Vulnerability CVE 2008 2364 
86%             SE44407 CLOSED PER      HTTPSVR-UNPRED HTTP VULNERABILITY 
CVE-2010-1452 
83%             SE62802 CLOSED PER      OSP-LWI IBM NAVIGATOR FOR I TLS 
SSL PROTOCOL USE 
See also:
https://www.ibm.com/blogs/psirt/
IBM Product Security Incident Response (PSIRT) blog.
This may help:
http://www-912.ibm.com/s_dir/sline003.NSF/554c38c4848b77f2862567bd0046e003/b3e91f2da858222c86257712006e3c36?OpenDocument
Rob Berendt
As an Amazon Associate we earn from qualifying purchases.