IBM Updates
3185Warning Date
Severity Level
Warning Number
Target Sector
4 June, 2020
● High
2020-1321
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Spectrum Conductor
- 2.4
- 2.4.1
- 2.3
- IBM Security Guardium
- 11.1
- IBM Cloud App Management V2018
- 2019.3.0
- 2019.4.0
- IBM Cloud App Management V2018
- 2019.3.0
- 2019.4.0
- Financial Transaction Manager for Corporate Payment Services for MP
- 2.1.1
- IBM QRadar SIEM
- 7.3
- 7.4
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS).
- Disclose sensitive information.
- Bypass security restrictions remotely.
- Execute arbitrary code.
- Decrypt highly sensitive information.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-three-vulnerabilities-in-nimbus-josejwt-affect-ibm-spectrum-conductor/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-use-of-a-broken-or-risky-cryptographic-algorithm-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-apache-cxf-affects-ibm-cloud-app-management-cve-2019-12406/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-kernel-vulnerability-10/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-python-affects-ibm-cloud-app-management-cve-2020-8492/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-improper-restriction-of-excessive-authentication-attempts-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-os-command-injection-vulnerabilities-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-java-runtime-affect-financial-transaction-manager-for-corporate-payment-services-v2-1-1-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-is-vulnerable-to-an-xml-external-entity-injection-xxe-attack-cve-2020-4509/