تنبيه IBM
2843تاريخ التحذير
مستوى الخطورة
رقم التحذير
القطاع المستهدف
23 يناير, 2022
● عالٍ جدًا
2022-4266
الكل
أصدرت IBM عدة تحديثات لمعالجة عدد من الثغرات في عدد من منتجاتها،أبرزها:
- IBM InfoSphere Information Server, Information Server on Cloud
- IBM Netcool Agile Service Manager
- IBM i
- IBM Cloud Pak for Data System 1.0 – Openshift Container Platform 3.11
- IBM Operational Decision Manager
- IBM Security Guardium
- IBM Operations Analytics Predictive Insights
التهديدات:
يمكن للمهاجم استغلال الثغرات وتنفيذ ما يلي:
- تنفيذ برمجيات خبيثة
- هجمة حجب الخدمة (DoS attack)
يوصي المركز بتحديث النسخ المتأثرة حيث أصدرتIBM توضيحًا لهذه التحديثات، أبرزها:
- Security Bulletin: IBM InfoSphere Information Server is vulnerable to denial of service and arbitrary code execution due to Apache Log4j (CVE-2021-45105, CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Netcool Agile Service Manager is vulnerable to arbitrary code execution and denial of service due to Apache Log4j (CVE-2021-44832, CVE-2021-45046, CVE-2021-45105) - IBM PSIRT Blog
- Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM i - IBM PSIRT Blog
- Security Bulletin: IBM QRadar hardware appliances are vulnerable to Intel privilege escalation (CVE-2021-0144) - IBM PSIRT Blog
- Security Bulletin: Log4j vulnerability CVE-2021-44228 affects IBM Cloud Pak for Data System 1.0 - IBM PSIRT Blog
- Security Bulletin: Vulnerability in Apache Log4j affects IBM Operational Decision Manager (CVE-2021-44228) - IBM PSIRT Blog
- Security Bulletin: IBM Security Guardium is vulnerable to a denial of service vulnerability in Apache log4j2 component (CVE-2021-45105 & CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Operations Analytics Predictive Insights is vulnerable to denial of service and arbitrary code execution due to Apache Log4j (CVE-2021-45105, CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Cognos Controller has addressed multiple vulnerabilities - IBM PSIRT Blog