IBM Updates
3062Warning Date
Severity Level
Warning Number
Target Sector
3 June, 2020
● Medium
2020-1310
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Business Automation Workflow
- V19.0
- V18.0
- IBM Business Process Manager
- V8.6
- V8.5
- IBM Security Guardium
- 11.1
- IBM Security Identity Manager
- 6.0.0
- 6.0.2
- IBM Prospect
- 8.0.7
- R42.2
- IBM Network Performance Insight
- 1.3
- 1.3.1
- ICP – Compare & Comply
- All versions
- RDS
- 5.2.1 iFix 13 and earlier
- RDA
- 6.0.0.2 iFix 06 and earlier
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS).
- Disclose sensitive information.
- Bypass security restrictions remotely.
- Cross-site scripting (XSS) attack.
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-in-ibm-sdk-for-node-js-might-affect-the-configuration-editor-used-by-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-left-over-debug-code-in-js-files-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-has-been-fixed-in-ibm-security-identity-manager-cve-2019-4561/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-prospect-is-affected-by-expat-xml-parser-vulnerability-cve-2019-15903/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-oracle-mysql-vulnerabilities-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-the-vanruability-net-sf-ehcache-blocking-in-fasterxml-jackson-databind-has-an-unknown-impact-found-network-performance-insight-cve-2019-17571/
- https://www.ibm.com/blogs/psirt/security-bulletin-websphere-application-server-liberty-is-vulnerable-to-cross-site-scripting-cve-2020-4303-cve-2020-4304-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-os-command-injection-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-hard-coded-passwords-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-security-guardium-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-rational-directory-server-tivoli-rational-directory-administrator-4/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-improper-access-control-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-use-of-hard-coded-credentials-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-cross-site-scripting-vulnerability/