IBM Updates
3080Warning Date
Severity Level
Warning Number
Target Sector
24 June, 2020
● High
2020-1395
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Watson Speech to Text, Text to Speech
- 1.0.1-1.1
- IBM Security Guardium
- 10.6
- 11.1
- Netcool/OMNIbus Integrations Probe for Network Node Manager i
- nco-p-hp-nnm-1_0 up to and including nco-p-hp-nnm-3_0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Execute arbitrary code remotely.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-speech-to-text-text-to-speech-icp-websphere-application-server-liberty-fix/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-oracle-mysql-vulnerabilities-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-os-command-injection-vulnerabilities-4/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-have-been-identified-in-ibm-tivoli-netcool-omnibus-probe-for-network-node-manager-i-cve-2009-3555/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-use-of-hard-coded-credentials-vulnerabilities-2/