IBM Updates
2987Warning Date
Severity Level
Warning Number
Target Sector
14 July, 2020
● High
2020-1486
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM QRadar SIEM
- 7.4.0 - 7.4.0 Patch 2
- 7.3.0 - 7.3.3 Patch 3
- FlashSystem 900 MTM: 9840-AE2 and 9843-AE2
- 1.5.2.6
- 1.6.1.1
- FlashSystem 840 MTM: 9840-AE1 and 9483-AE1
- 1.5.2.6
- FlashSystem V9000 storage enclosure MTM: 9846-AE3 and 9848-AE3
- 1.5.2.6
- 1.6.1.
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Obtain sensitive information.
- Remote code execution.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-cross-site-scripting-cve-2020-4364/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-command-injection-cve-2020-4512/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-using-components-with-known-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-denial-of-service-cve-2020-4511/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-java-affect-the-ibm-flashsystem-900-cve-2019-2989-and-cve-2019-2964/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-vulnerable-to-cross-site-scripting-cve-2020-4513/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-is-vulnerable-to-an-xml-external-entity-injection-xxe-attack-cve-2020-4510/
- https://www.ibm.com/blogs/psirt/security-bulletin-apache-tika-as-used-by-ibm-qradar-siem-is-vulnerable-to-a-denial-of-service-cve-2020-1951-cve-2020-1950/