Your review has been sent successfully

IBM Updates

1855
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

6 December, 2020

● High

2020-2148

All

Description:

IBM has released security updates to address multiple vulnerabilities in the following products:

  • IBM Tivoli Application Dependency Discovery Manager
    • 7.3.0.0 – 7.3.0.8
  • IBM Blockchain Platform (Software/on-prem)
  • Trusteer Mobile SDK
  • IBM Business Automation Workflow
    • 19.0.0.x
    • 20.0.0.1
  • IBM Emptoris Strategic Supply Management Platform
    • 10.1.0.x
    • 10.1.1.x
    • 10.1.3.x
  • IBM Watson Explorer Deep Analytics Edition Foundational and Analytical Components
    • 12.0.0.0
    • 12.0.1
    • 12.0.2.0 – 12.0.2.2
    • 12.0.3.0 – 12.0.3.4
  • IBM Watson Explorer Deep Analytics Edition oneWEX
    • 12.0.0.0
    • 12.0.0.1
    • 12.0.1
    • 12.0.2.0 – 12.0.2.2
    • 12.0.3.0 – 12.0.3.4
  • IBM Watson Explorer Foundational Components
    • 10.0.0.0 – 10.0.0.9
    • 11.0.0.0 – 11.0.0.3
    • 11.0.1
    • 11.0.2.0 – 11.0.2.8
  • IBM Watson Explorer Foundational Components Annotation Administration Console
    • 12.0.0.0
    • 12.0.1
    • 12.0.2.0 – 12.0.2.2
    • 12.0.3.0 – 12.0.3.4
    • 11.0.0.0 – 11.0.0.3
    • 11.0.1
    • 11.0.2.0 – 11.0.2.8
    • 10.0.0.0 – 10.0.0.6
  • IBM Watson Explorer Analytical Components
    • 11.0.0.0 – 11.0.0.3
    • 11.0.1
    • 11.0.2.0 – 11.0.2.8
    • 10.0.0.0 – 10.0.0.2
  • IBM Watson Explorer Content Analytics Studio
    • 12.0.0
    • 12.0.1
    • 12.0.2
    • 12.0.3
    • 11.0.0.0 – 11.0.0.3,
    • 11.0.1
    • 11.0.2.0 – 11.0.2.2
  • IBM API Connect
    • 10.0
    • 2018.4.1.0-2018.4.1.11
  • IBM Emptoris Spend Analysis, Contract Management, Sourcing and Program Management
    • 10.1.3.x
    • 10.1.1.x
    • 10.1.0.x
  • IBM Spectrum Protect Plus Container Agent for Kubernetes - Linux
    • 10.1.5-10.1.6
  • IBM Spectrum Protect Plus Microsoft File Systems Agent (Windows)
    • 10.1.6
  • IBM Spectrum Protect Plus
    • 10.1.0-10.1.6

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service (DoS)
  • Cross-site scripting (XSS)
  • Bypass security restrictions
  • Obtain sensitive information
  • Remote arbitrary code execution

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 6 December, 2020

Rate the content

rate-icon
up icon