IBM Updates
2797Warning Date
Severity Level
Warning Number
Target Sector
13 October, 2020
● High
2020-1905
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM Business Automation Workflow
- V20.0
- V19.0
- V18.0
- IBM Business Process Manager
- V8.6
- V8.5
- IBM® SDK Java™ Technology Edition 8.0.6.15
- RFT 9.2, 9.1, 9.5, 8.6
- IBM Netezza Host Management
- 5.4.9.0 – 5.4.28.0
- IBM® Runtime Environment Java™ Versions 7.0, 7.1, and 8.0
- SPSS Statistics 27.0, 26.0, 25.0, 24.0, 23.0
- IBM Cloud Pak System
- 2.2.6
- 2.3.0.1
- 2.3.1.1
- 2.3.2.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Obtain sensitive information.
- Cross-site scripting (XSS) attack.
- Denial of service (DoS).
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-publicly-disclosed-vulnerability-from-qemu-affects-ibm-netezza-host-management-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-docker-affects-cloud-pak-sytem-cve-2020-13401/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-java-runtime-affects-ibm-spss-statistics-6/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affecting-rational-functional-tester-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-vulnerabilities-in-jquery-might-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2020-7656-cve-2020-11022-cve-2020-11023-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-publicly-disclosed-vulnerability-from-kernel-affects-ibm-netezza-host-management-11/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affecting-rational-functional-tester-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-vulnerability-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2020-4698-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-vulnerability-affect-ibm-business-automation-workflow-and-ibm-business-process-manager-bpm-cve-2020-4557-3/