IBM Updates
2960Warning Date
Severity Level
Warning Number
Target Sector
26 February, 2020
● Medium
2020-963
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- TPF Toolkit
- 4.6, 4.2
- IBM Sterling B2B Integrator
- 5.2.0.0 – 5.2.6.5
- WA for ICP
- 1.3.0
- WebSphere Service Registry and Repository
- 8.5
- IBM Tivoli Composite Application Manager for SOA
- v7.2.0 – 7.2.0.1 Interim Fix 15
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site request forgery (CSRF).
- SQL injection.
- Obtain sensitive version information.
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-and-ibm-java-runtime-affect-tpf-toolkit/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-scripting-vulnerability-affects-ibm-sterling-b2b-integrator-dashboard-user-interface-cve-2019-4596/
- https://www.ibm.com/blogs/psirt/security-bulletin-java-update/
- https://www.ibm.com/blogs/psirt/security-bulletin-information-disclosure-vulnerability-in-ibm-websphere-service-registry-and-repository-cve-2019-4537/
- https://www.ibm.com/blogs/psirt/security-bulletin-cross-site-request-forgery-affects-ibm-sterling-b2b-integrator-cve-2019-4726/
- https://www.ibm.com/blogs/psirt/security-bulletin-sql-injection-vulnerability-affects-ibm-sterling-b2b-integrator-dashboard-user-interface-cve-2019-4598/
- https://www.ibm.com/blogs/psirt/security-bulletin-sql-injection-vulnerability-affects-ibm-sterling-b2b-integrator-ebics-cve-2019-4597/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-itcam-for-soa/