IBM Updates
2834Warning Date
Severity Level
Warning Number
Target Sector
7 July, 2020
● Medium
2020-1448
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Db2
- V9.7
- V10.1
- V10.5
- V11.1
- V11.5
- IBM i
- 7.4
- 7.3
- 7.2
- 7.1
- Financial Transaction Manager for ACH Services for Multi-Platform
- 3.1.0
- 3.0.6
- ART/Agent
- 8.1.5
- 8.1.5.1
- 8.1.5.2
- 8.1.5.3
- 8.1.5.4
- 8.1.5.5
- 8.1.5.6
- 8.1.6
- 8.1.6.1
- 8.1.6.2
- 8.1.6.3
- 8.1.6.4
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Obtain sensitive information.
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-an-information-disclosure-vulnerability-in-ibm-websphere-libtery-affects-ibm-license-key-server-administration-reporting-tool-and-administration-agent/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-an-information-disclosure-cve-2020-4387-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-buffer-overflow-leading-to-a-privileged-escalation-cve-2020-4363-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-java-runtime-affect-financial-transaction-manager-for-ach-services-cve-2020-2654/
- https://www.ibm.com/blogs/psirt/security-bulletin-bind-for-ibm-i-is-affected-by-cve-2020-8616-and-cve-2020-8617/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-an-information-disclosure-cve-2020-4386-2/