IBM Updates
2856Warning Date
Severity Level
Warning Number
Target Sector
16 July, 2020
● Medium
2020-1512
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Tivoli System Automation Application Manager
- 4.1
- FlashSystem 900 MTM: 9840-AE2 and 9843-AE2
- 1.5.2.6
- 1.6.1.1
- FlashSystem 840 MTM: 9840-AE1 and 9483-AE1
- 1.5.2.6
- FlashSystem V9000 storage enclosure MTM: 9846-AE3 and 9848-AE3
- 1.5.2.6
- 1.6.1.1
- System x3250 M5 5458
- JUE1
- System x3100 M5 5457
- J9E1
- IBM Secure Proxy
- 6.0
- 6.0.1
- IBM Sterling Secure Proxy
- 3.4.3.2
- 3.4.2
- IBM External Authentication Server
- 6.0.1
- 6.0
- IBM Sterling External Authentication Server
- 2.4.3.2
- 2.4.2
- IBM Rational Publishing Engine
- 6.0.6.1
- 6.0.6
- PUB
- 7.0
- IBM Netezza Host Management
- 5.4.9.0 – 5.4.26.0
- ETM
- 7.0
- RQM
- 6.0.6.1
- 6.0.6
- 6.0.2
- DOORS Next
- 7.0
- RDNG
- 6.0.2
- 6.0.6.1
- 6.0.6
- EWM
- 7.0
- RTC
- 6.0.2
- 6.0.6.1
- 6.0.6
- ELM
- 7.0
- CLM
- 6.0.6.1
- 6.0.6
- 6.0.2
- RDM
- 7.0
- Rhapsody DM
- 6.0.6
- 6.0.6.1
- 6.0.2
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Obtain sensitive information.
Best practice and Recommendations:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-application-manager-apr-2020-cpu-cve-2020-2805-cve-2020-2803-cve-2020-2757-cve-2020-2756/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-java-affect-the-ibm-flashsystem-900-cve-2019-2989-and-cve-2019-2964-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-for-multiplatforms-apr-2020-cpu/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-has-released-a-unified-extensible-firmware-interface-uefi-fix-in-response-to-an-intel-escalation-of-information-disclosure-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-xml-external-entity-injection-xxe-vulnerability-affects-ibm-secure-proxy-cve-2020-4462/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-java-runtime-vulnerability-affects-ibm-sterling-external-authentication-server-cve-2020-2781/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-java-runtime-vulnerability-affects-ibm-secure-proxy-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-session-cookie-is-missing-secure-attribute-and-affects-ibm-publishing-engine/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-java-runtime-vulnerability-affects-ibm-sterling-secure-proxy-cve-2020-2781/
- https://www.ibm.com/blogs/psirt/security-bulletin-publicly-disclosed-vulnerabilities-from-kernel-affect-ibm-netezza-host-management-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-for-multiplatforms-jan-2020-cpu-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-vulnerability-affects-ibm-jazz-foundation-and-ibm-engineering-products/
- https://www.ibm.com/blogs/psirt/security-bulletin-http-header-weakness-affects-ibm-secure-external-authentication-server/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-java-runtime-vulnerability-affects-ibm-secure-external-authentication-server-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-application-manager-jan-2020-cpu-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-missing-cookie-attribute-vulnerability-affects-ibm-secure-proxy/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-and-vulnerable-library-jquery-v1-11-1-affects-ibm-engineering-workflow-management/
- https://www.ibm.com/blogs/psirt/security-bulletin-xml-external-entity-injection-xxe-vulnerability-affects-ibm-secure-external-authentication-server-cve-2020-4462/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-application-manager-oct-2019-cpu-cve-2019-2949/