IBM Updates
3027Warning Date
Severity Level
Warning Number
Target Sector
9 December, 2019
● High
2019-701
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM SAN Volume Controller
- IBM FlashSystem V9000, 9100 Family
- IBM Storwize V7000, V5000, V3700, V3500
- IBM Spectrum Virtualize Software
- IBM Planning Analytics
- IBM Tivoli Business Service Manager
- Watson Assistant for IBM Cloud Pak for Data
- IBM DataPower Gateway
- IBM Watson Machine Learning CE
- IBM PowerAI
- gpfs.tct.server
- ICP – Discovery
- Netcool Operations Insight – Cloud Native Event Analytics
- IBM ToolsCenter Dynamic System Analysis (DSA) Preboot
- IBM Spectrum Virtualize for Public Cloud
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Code injection
- Escalation of privilege
- Unauthorized disclosure of information
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: https://www.ibm.com/blogs/psirt/