IBM Updates
2588Warning Date
Severity Level
Warning Number
Target Sector
21 July, 2020
● Critical
2020-1525
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Tivoli System Automation for Multiplatforms
- 4.1
- IBM Watson Machine Learning Community Edition
- 1.6.2
- 1.7.0
- IBM Cloud Object Storage Systems
- 3.14.12.32 and prior
- 3.14.12.49 and prior
- DataQuant for z/OS
- 2.1
- DataQuant for Multiplatforms
- 2.1
- IBM Sterling B2B Integrator
- 6.0.0.0 – 6.0.3.1
- 5.2.6.2 – 5.2.6.5_1
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Remote code execution.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-ibm-tivoli-system-automation-for-multiplatforms-oct-2019-cpu-cve-2019-2949/
- https://www.ibm.com/blogs/psirt/security-bulletin-wml-ce-sqlite-through-3-32-0-has-an-integer-overflow-in-sqlite3_str_vappendf-in-printf-c/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-object-storage-systems-july-2020v1/
- https://www.ibm.com/blogs/psirt/security-bulletin-sb003732/
- https://www.ibm.com/blogs/psirt/security-bulletin-wml-ce-tensorflow-in-sqlite-before-3-32-3-select-c-mishandles-query-flattener-optimization/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-in-jackson-databind-affect-b2b-api-of-ibm-sterling-b2b-integrator-3/