IBM Updates
2493Warning Date
Severity Level
Warning Number
Target Sector
23 May, 2020
● High
2020-1273
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- Initial Release
- 2.0.0
- Vyatta 5600
- IBM Security Guardium
- 10.6
- 11.0
- 11.1
- IBM Kenexa LCMS Premier on premise
- LCMS Premier 13.1.0 and below
- InfoSphere Streams
- 4.1.1.x
- 4.2.1.x
- 4.3.1.x
- IBM Kenexa LMS on premise
- premiseLMS 6.1 and below
- IBM Spectrum Control
- 5.3.0 - 5.3.6
- RSA
- 9.7x
- 9.6x
- 9.5x
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack.
- Obtain sensitive information
- Denial of service (DoS)
- Execute arbitrary code remotely
- Man in the Middle (MitM)
- Take control of the affected system
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/support/pages/node/6214293
- https://www.ibm.com/support/pages/node/6214332
- https://www.ibm.com/support/pages/node/6214488
- https://www.ibm.com/support/pages/node/6214358
- https://www.ibm.com/support/pages/node/6214294
- https://www.ibm.com/support/pages/node/6212670
- https://www.ibm.com/support/pages/node/6207090
- https://www.ibm.com/support/pages/node/6212435
- https://www.ibm.com/support/pages/node/6212441
- https://www.ibm.com/support/pages/node/6207084
- https://www.ibm.com/support/pages/node/6212419
- https://www.ibm.com/support/pages/node/6207088
- https://www.ibm.com/support/pages/node/6212156
- https://www.ibm.com/support/pages/node/6212158
- https://www.ibm.com/support/pages/node/6212720
- https://www.ibm.com/support/pages/node/6212591
- https://www.ibm.com/support/pages/node/6212155
- https://www.ibm.com/support/pages/node/6207092
- https://www.ibm.com/support/pages/node/6212157
- https://www.ibm.com/support/pages/node/6212743