Your review has been sent successfully

IBM Updates

1803
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

16 December, 2020

● High

2020-2214

All

Description:

IBM has released security updates to address several vulnerabilities in the following products:

  • IBM Tivoli Netcool Impact 7.1.0
    • 7.1.0.0~7.1.0.19 Interim Fix 7
  • IBM Cloud Pak for Multicloud Management Infrastructure Management
    • 2.0
    • 2.1
  • IBM WebSphere Cast Iron Solution
    • 7.0.0.x Marked as Invalid
    • 7.5.0.x Marked as Invalid
  • WebSphere Cast Iron
    • v 7.5.0.0, 7.5.0.1, 7.5.1.0
    • v 7.0.0.0, 7.0.0.1, 7.0.0.2
  • App Connect Professional
    • v 7.5.2.0
    • v 7.5.3.0
    • v 7.5.4.0
  • IBM Tivoli Netcool System Service Monitors/Application Service Monitors
    • 4.0.1
  • IBM Tivoli Netcool Impact 7.1.0
    • 7.1.0.0~7.1.0.19 Interim Fix 7
  • IBM QRadar
    • 7.3.0 - 7.3.3 Patch 5
    • 7.4.0 - 7.4.1 Patch 1
  • IBM Cloud Pak for Multicloud Management Infrastructure Management
    • 2.0
    • 2.1
  • IBM Flex System EN2092 1Gb Ethernet Scalable Switch
    • 7.8
  • IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
    • 7.8
  • IBM Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
    • 7.8
  • IBM Flex System CN4093 10Gb Converged Scalable SwitchIBM Flex System CN4093 10Gb Converged Scalable Switch
    • 7.8
  • IBM RackSwitch firmware
  • IBM Cloud Event Management on IBM Cloud Private
  • IBM Sterling File Gateway
    • 2.2.0.0 – 6.0.3.2
  • Netcool Operations Insight – Cloud Native Event Analytics
    • 1.6.x
  • IBM Tivoli Netcool/OMNIbus_GUI
    • 8.1.x
  • IBM Sterling B2B Integrator
    • 5.2.0.0 – 6.0.3.2
  • IBM Flex System switch firmware
  • IBM Financial Transaction Manager for SWIFT Services for Multiplatforms
    • 3.2.4
  • IBM Netezza for Cloud Pak for Data
  • IBM WebSphere Application Server in IBM Cloud
    • 9.0
    • 8.5
    • Liberty
  • App Connect Enterprise Certified Container
    • 1.0.0 with Operator
    • 1.0.1 with Operator
    • 1.0.2 with Operator
    • 1.0.3 with Operator
    • 1.0.4 with Operator
    • 1.0.5 with Operator
  • Netcool Operations Insight – Cloud Native Event Analytics
    • 1.6.x

Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Buffer overflow
  • Execute arbitrary code
  • Elevate privileges

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 16 December, 2020

Rate the content

rate-icon
up icon