IBM Updates
3230Warning Date
Severity Level
Warning Number
Target Sector
10 October, 2019
● High
2019-511
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- Maximo Asset Management 7.6
- Maximo for Aviation
- Maximo for Life Sciences
- Maximo for Nuclear Power
- Maximo for Oil and Gas
- Maximo for Transportation
- Maximo for Utilities
- SmartCloud Control Desk
- IBM Control Desk
- Tivoli Integration Composer
- IBM Spectrum Scale V5.0.0.0 through V5.0.3.2, V4.2.0.0 through V4.2.3.17
- These vulnerabilities affect Node.js v8.15.1, v10.15.2, v12.7.1 and earlier releases.
- IBM Maximo Anywhere versions 7.6.2, 7.6.3, 7.6.1 and 7.6.0
- SPSS Modeler 17.0.0.1 and earlier IBM SPSS Modeler 17.1.0.0 IBM SPSS Modeler 18.0.0.2 and earlier IBM SPSS Modeler 18.1.0.0 IBM SPSS Modeler 18.2.0.0 IBM SPSS Modeler 18.2.1.1 and earlier.
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS).
- Elevate privileges.
- Obtain Sensitive information.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: https://www.ibm.com/blogs/psirt/