Your review has been sent successfully

IBM Updates

2426
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

18 March, 2020

● Medium

2020-1039

All

Description:

IBM has released security updates to address multiple vulnerabilities in the following products:

  • Liberty for Java
    • 3.37
  • eDiscovery Analyzer
    • 2.2.2
  • IBM Content Classification
    • 8.8
  • ART
    • 8.1.5.6
    • 8.1.5.1
    • 8.1.5.2
    • 8.1.5.3
    • 8.1.6
    • 8.1.5.4
    • 8.1.6.1
    • 8.1.5.5
    • 8.1.5
  • IBM MobileFirst Platform Foundation
    • 7.1.0.0
  • IBM MobileFirst Foundation
    • 8.0.0.0
  • IBM Security Guardium
    • 10.6-10.0
    • 11.0
  • IBM Tivoli Netcool/OMNIbus_GUI
    • 8.1.x
  • All supported versions (10.x, and 12.x) of Node.js are vulnerable.
  • IBM Operations Analytics Predictive Insights
    • All versions
  • WebSphere Message Broker
    • V8.0.0.0 – V8.0.0.9
  • IBM App Connect Enterprise
    • V11 , V11.0.0.0 – V11.0.0.7
  • IBM Integration Bus
    • V10.0.0.0 – V10.0.0.19
  • IBM Integration Bus
  • V9.0.0.0 – V9.0.0.11
  • IBM DataPower Gateway
    • 2018.4.1.0-2018.4.1.9
  • eDiscovery Analyzer
    • 2.2.2

Threats:

  • Take control of the system.
  • Denial of service (DoS).
  • Execute arbitrary code.
  • Obtain sensitive information.
  • Cross-site request forgery.
  • Bypass web application firewall protection.
  • Bypass security restrictions.

Best practice and Recommendations:

The CERT team encourages users to apply the necessary updates according to the link below:

Last updated at 18 March, 2020

Rate the content

rate-icon
up icon