IBM Updates
2596Warning Date
Severity Level
Warning Number
Target Sector
8 July, 2020
● Medium
2020-1462
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Emptoris Contract Management
- 10.1.3.x,10.1.1.x, 10.1.0.x
- PUB
- 7.0
- RPE
- 6.0.6.1
- 6.0.6
- IBM Emptoris Program Management
- 10.1.3.x,10.1.1.x, 10.1.0.x
- IBM Emptoris Strategic Supply Management Platform
- 10.1.0.x,10.1.1.x,10.1.3.x
- IBM Cloud Pak System
- 2.3.0.1 – 2.3.1.1
- 2.2.5 – 2.2.6
- IBM Emptoris Supplier Lifecycle Mgmt
- 10.1.3.x,10.1.1.x, 10.1.0.x
- IBM Emptoris Sourcing
- 10.1.3.x,10.1.1.x, 10.1.0.x
- Carbon Black Response
- 1.0.1 – 1.3.0
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS).
- Obtain sensitive information.
- Execute arbitrary code remotley.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/support/pages/node/6244562
- https://www.ibm.com/support/pages/node/6244628
- https://www.ibm.com/support/pages/node/6244560
- https://www.ibm.com/support/pages/node/6244572
- https://www.ibm.com/support/pages/node/6244618
- https://www.ibm.com/support/pages/node/5695299
- https://www.ibm.com/support/pages/node/6244564
- https://www.ibm.com/support/pages/node/6244554
- https://www.ibm.com/support/pages/node/6244620