IBM Updates
3197Warning Date
Severity Level
Warning Number
Target Sector
6 October, 2019
● High
2019-490
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM MQ V8 versions 8.0.0.4 – 8.0.0.12
- IBM MQ V9.0LTS versions 9.0.0.0 – 9.0.0.6
- IBM MQ V9.1 LTS versions 9.1.0.0 – 9.1.0.2
- IBM MQ V9.1 CD versions 9.1.0 – 9.1.2
- IBM Connect:Direct Web Services from version 5.3 to 6.0.0.3
- IBM Installation Manager and IBM Packaging Utility versions 1.9 and earlier.
- IBM Security Key Lifecycle Manager v2.6 – 2.6.0.5, v2.7 – 2.7.0.4, (SKLM) v3.0 – v3.0.0.2, (SKLM) v3.0.1- v3.0.1.1
- · QRadar / QRM / QVM / QRIF / QNI 7.2 to 7.2.8 Patch 16 · QRadar / QRM / QVM / QRIF / QNI 7.3 to 7.3.2 Patch 3
- Rational Collaborative Lifecycle Management 6.0 – 6.0.6.1
- Rational Quality Manager 6.0 – 6.0.6.1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Sensitive information disclosure-remotely.
- Cross-site scripting (XSS).
- Denial of service attack (DoS).
- Code injection.
- Escalation of privilege.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: https://www.ibm.com/blogs/psirt/