IBM Updates
3149Warning Date
Severity Level
Warning Number
Target Sector
22 October, 2019
● High
2019-547
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM HTTP Server 8.5.5 to 8.5.5.12
- IBM HTTP Server 8.5.5 to 8.5.5.15
- IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.4, 2.4.0.1, 2.4.0.2, 2.4.0.3, 2.4.0.4, 2.4.0.5
- IBM Cloud Event Management on IBM Cloud Private Version 2.3.0
- IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.5, V2.5.0.1, V2.5.02. V2.5.0.3, V2.5.0.4, V2.5.0.5, V2.5.0.6, V2.5.0.7, V2.5.0.8, V2.5.0.9, V2.4, V2.4.0.1, V2.4.0.2, V2.4.0.3, V2.4.0.4, V2.4.0.5
- IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5, 2.5.0.1, 2.5.0.2, 2.5.0.3, 2.5.0.4, 2.5.0.5, 2.5.0.6, 2.5.0.7, 2.5.0.8, 2.5.0.9
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Man in the middle attack.
- Escalation of privilege.
- Execute arbitrary code.
- Denial of service attack (DoS).
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: https://www.ibm.com/blogs/psirt/