IBM Updates
2834Warning Date
Severity Level
Warning Number
Target Sector
20 August, 2020
● High
2020-1660
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Content Navigator
- 3.0CD
- IBM Spectrum Protect Plus
- 10.1.0-10.1.6
- IBM Db2
- V9.7
- V10.1
- V10.5
- V11.1
- V11.5
- IBM Business Automation Workflow
- V19.0
- V18.0
- IBM Business Process Manager
- V8.6
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary commands.
- buffer overflow.
- Information disclosure.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-navigator-is-susceptible-to-a-sensitive-data-exposure/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-bash-affects-ibm-spectrum-protect-plus-cve-2019-9924-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-vulnerable-to-buffer-overflow-leading-to-a-privileged-escalation-cve-2020-4363-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-manager-is-affected-by-a-potential-information-disclosure-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-navigator-is-vulnerable-to-an-elliptic-curve-key-disclosure/
- https://www.ibm.com/blogs/psirt/security-bulletin-autocomplete-not-disabled-for-password-field-in-ibm-content-navigator/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-navigator-is-vulnerable-to-improper-input-validation/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-snakeyaml-might-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2017-18640/