IBM Updates
3924Warning Date
Severity Level
Warning Number
Target Sector
26 August, 2020
● Medium
2020-1685
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- WebSphere Application Server
- 9.0
- 8.0
- 8.5
- TNPM Wireline
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- SPSS Collaboration and Deployment Services
- 8.2
- 8.2.1
- IBM CICS Transaction Gateway
- 9.1.0.0 – 9.1.0.3
- 9.2.0.0 – 9.2.0.2
- 9.0.0.0 – 9.0.0.4
- 8.1.0.0 – 8.1.0.5
- 8.0.0.0 – 8.0.0.6
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Information disclosure.
- Man in the middle attack.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-batik-affects-websphere-application-server-cve-2019-17566/
- https://www.ibm.com/blogs/psirt/security-bulletin-beast-security-vulnerability-in-ibm-tivoli-netcool-performance-manager-for-wireline-cve-2011-3389/
- https://www.ibm.com/blogs/psirt/security-bulletin-kerberos-vulnerability-in-ibm-java-runtime-affects-collaboration-and-deployment-services/
- https://www.ibm.com/blogs/psirt/security-bulletin-august-2020-cve-2020-2654-in-ibm-java-runtime-affect-cics-transaction-gateway/