IBM Updates
2510Warning Date
Severity Level
Warning Number
Target Sector
30 May, 2021
● Critical
2021-2978
All
Description:
IBM has released a security update to address several vulnerabilities in the following products:
- IBM Application Gateway
- 1.0
- IBM Cognos Analytics
- 11.1
- 11.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Buffer overflow
- Sensitive information disclosure
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cognos-analytics-has-addressed-multiple-vulnerabilities-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-have-been-resolved-in-ibm-application-gateway-cve-2021-20576-cve-2021-20575-cve-2021-29665/
- https://www.ibm.com/blogs/psirt/security-bulletin-cve-2021-2161-may-affect-ibm-sdk-java-technology-edition-3/