IBM Updates
2696Warning Date
Severity Level
Warning Number
Target Sector
23 February, 2020
● High
2020-949
All
Description:
IBM has released an updates to address a vulnerabilities in the following products:
- IBM WebSphere Application Server used by IBM License Metric Tool
- StoredIQ
- 7.6.0
- IBM Sterling B2B Integrator
- 5.2.0.0 – 5.2.6.5
- IBM API Connect
- 5.0.0.0-5.0.8.7
- PowerSC
- 1.2
- 1.3
- IBM Maximo Asset Management
- 7.6.1.0
- IBM Cloud Object Storage Systems
- Watson Machine Learning Community Edition
- 1.6.2
- 1.6.1
- IBM PowerAI
- 1.6.0
- IBM Spectrum Protect Plus
- 10.1.0-10.1.5
- IBM MobileFirst Platform Foundation
- 7.1.0.0 – using the scripts (BYOL)
- IBM MobileFirst Foundation
- 8.0.0.0 – ICP, IKS or using the scripts (BYOL)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service
- Obtain sensitive information
- Elevated privileges
- Security bypass
- Execute arbitrary code remotely
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-websphere-application-server-affects-ibm-license-metric-tool-v9-cve-2019-4441/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-identified-in-ibm-storediq/
- https://www.ibm.com/blogs/psirt/security-bulletin-phishing-attack-vulnerability-affects-ibm-sterling-b2b-integrator-cve-2019-4595/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-api-connect-v5-is-impacted-by-a-denial-of-service-vulnerability-in-linux-kernel-cve-2019-11477/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-curl-affect-powersc-cve-2019-5481-cve-2019-5482/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-path-disclosure-cve-2019-4745/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-object-storage-systems-february-2020v2/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-identified-in-libjpeg-turbo-shipped-with-powerai/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-fasterxml-jackson-databind-affect-ibm-spectrum-protect-plus-cve-2019-16943-cve-2019-16942-cve-2019-17531-cve-2019-17267-cve-2019-14540-cve-2019-163/
- https://www.ibm.com/blogs/psirt/security-bulletin-information-disclosure-in-ibm-spectrum-protect-plus-cve-2019-4703/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-linux-kernel-affect-ibm-spectrum-protect-plus/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-samba-affect-ibm-spectrum-protect-plus-cve-2019-14833-cve-2019-14847-cve-2019-10218/
- https://www.ibm.com/blogs/psirt/security-bulletin-command-injection-vulnerabilities-in-ibm-spectrum-protect-plus-cve-2020-4210-cve-2020-4213-cve-2020-4222-cve-2020-4212-cve-2020-4211/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-commons-compress-affects-ibm-spectrum-protect-plus-cve-2019-12402/
- https://www.ibm.com/blogs/psirt/security-bulletin-websphere-liberty-susceptible-to-http2-implementation-vulnerablility/