The site states, "This vulnerability exists in all software versions until the first fixed release", yet it only shows "3.1(5.0)" as a "Known Affected Releases." Are all versions affected since there hasn't been a fixed release or is 3.1(5.0) the only "Known Affected Releases:"
Typical Cisco and more confusing information which does not help us.
Ok, I bit the bullet and logged a TAC.
This is the reply.
"Be advised that CSCve37646 affects all versions of PI from 3.1.5 upwards and has recently been marked as remediated in version 3.3.1u2 which is scheduled to be released over the next month."