IBM Updates
2577Warning Date
Severity Level
Warning Number
Target Sector
23 January, 2020
● High
2020-837
All
Description:
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM PowerAI
- IBM Integrated Management Module II (IMM2) for System x and Flex
- IBM Integrated Management Module II (IMM2) for BladeCenter
- Watson Machine Learning Community Edition
- Watson Machine Learning Accelerator
- IBM Security Information Queue (ISIQ)
- WebSphere Application Server Liberty
- IBM Cognos Planning
- IBM Cast Iron
- App Connect Professional
- IBM IoT MessageSight
- AIX
- VIOS
- WebSphere MQ for HPE NonStop Server (Itanium)
- FOS
- UCD - IBM UrbanCode Deploy
- IBM WebSphere Message Broker Hypervisor Edition
- IBM Cloud Pak System
- IBM OS Image for AIX Systems
- IBM Jazz Reporting Service (JRS)
- IBM QRadar SIEM
- Jazz for Service Management
- Rational Asset Analyzer
- IBM SAN Volume Controller
- IBM Storwize
- IBM FlashSystem
- IBM Spectrum Virtualize Software
- IBM Spectrum Virtualize for Public Cloud
- IBM Spectrum Conductor with Spark
- IBM Spectrum Conductor
- IBM PowerAI Vision
- IBM API Connect
- IBM Db2
- OS Image for Red Hat Linux
- IBM BladeCenter Advanced Management Module
- IBM BladeCenter T Advanced Management Module
- API Connect
- WebSphere Cast Iron
- IBM BladeCenter Advanced Management Module (AMM)
- IBM BladeCenter T Advanced Management Module (AMM)
- IBM Integration Bus Hypervisor Editio
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code remotely
- Man-in-the-Middle (MitM)
- Obtain sensitive information
- Authentication bypass
- Denial of service (DoS)
- Privilege escalation
- Information disclosure.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory that published in 21 January and 22 January and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/page/1/
- https://www.ibm.com/blogs/psirt/page/2/
- https://www.ibm.com/blogs/psirt/page/3/
- https://www.ibm.com/blogs/psirt/page/4/
- https://www.ibm.com/blogs/psirt/page/5/
- https://www.ibm.com/blogs/psirt/page/6/
- https://www.ibm.com/blogs/psirt/page/7/
- https://www.ibm.com/blogs/psirt/page/8/