IBM Updates
2627Warning Date
Severity Level
Warning Number
Target Sector
14 October, 2020
● High
2020-1913
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM MQ Appliance
- 9.1 LTS
- 9.2
- 9.1 CD
- IBM QRadar - Info-ZIP UnZip
- SIEM 7.4.0 – 7.4.1 GA
- SIEM 7.3.0 – 7.3.3 Patch 4
- IBM Security Access Manager
- 9.0
- IBM Security Guardium
- 11.1
- 11.2
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Obtain sensitive information.
- Bypass security restrictions.
- Denial of service (DoS).
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-appliance-is-affected-by-an-information-disclosure-vulnerability-cve-2020-4528/
- https://www.ibm.com/blogs/psirt/security-bulletin-unzip-as-used-by-ibm-qradar-siem-is-vulnerable-to-denial-of-service-cve-2019-13232/
- https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-have-been-fixed-in-ibm-security-access-manager/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-apache-derby-as-used-by-ibm-qradar-siem-is-vulnerable-to-improper-input-validation-cve-2018-1313/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-a-jackson-databind-vulnerability-4/