IBM Updates
3100Warning Date
Severity Level
Warning Number
Target Sector
10 December, 2019
● Medium
2019-704
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Watson Studio Local 1.2.3
- WebSphere Application Server Liberty 17.0.0.3 – 19.0.0.11
- IBM Cloud Pak System 2.3, 2.3.0.1
- IBM SDK, Java Technology Editions used with WebSphere Application Server Liberty
- IBM SDK, Java Technology Editions used with IBM WebSphere Application Server Traditional Version 9.0.0.0 through 9.0.5.1, 8.5.0.0 through 8.5.5.16.
- IBM SDK, Java Technology Editions shipped in Application Client for IBM WebSphere Application Server Version 9.0.0.0 through 9.0.5.1, 8.5.0.0 through 8.5.5.16.
- Liberty 9.0, 8.5
- IBM Integration Bus Hypervisor Edition 9.0
Threats:
Remote attacker could exploit these vulnerabilities by doing the following: .
- Denial of service attack (DoS).
- Cross-site scripting (XSS).
- Sensitive information disclosure.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: https://www.ibm.com/blogs/psirt/