IBM Updates
2661Warning Date
Severity Level
Warning Number
Target Sector
18 February, 2020
● Medium
2020-926
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM TXSeries for Multiplatforms
- 9.1، 8.2، 8.1
- IBM Netcool Agile Service Manager
- 1.1
- IBM Content Collector for SAP Applications
- 4.0
- Log Analysis
- 1.3.1، 1.3.2، 1.3.3، 1.3.4، 1.3.5، 1.3.6
- IBM CICS TX on Cloud
- 10.1
- IBM Watson Explorer Deep Analytics Edition Foundational Components
- 12.0.0.0, 12.0.0.1, 12.0.1, 12.0.2.0 – 12.0.2.2, 12.0.3, 12.0.3.1
- IBM Watson Explorer Deep Analytics Edition Analytical Components
- 12.0.0.0, 12.0.0.1, 12.0.1, 12.0.2.0 – 12.0.2.2, 12.0.3, 12.0.3.1
- IBM Watson Explorer Deep Analytics Edition oneWEX
- 12.0.0.0, 12.0.0.1, 12.0.1, 12.0.2.0 – 12.0.2.2, 12.0.3, 12.0.3.1
- IBM Watson Explorer Foundational Components
- 10.0.0.0 – 10.0.0.6
- IBM Watson Explorer Foundational Components Annotation Administration Console
- 12.0.0.0, 12.0.1,12.0.2.0 – 12.0.2.2, 12.0.3, 12.0.3.1, 11.0 – 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 – 11.0.2.5, 10.0 – 10.0.0.6
- Watson Explorer Analytical Components
- 11.0 – 11.0.0.3, 11.0.1, 11.0.2, 11.0.2.1 – 11.0.2.5
- Watson Explorer Analytical Components
- 10.0 – 10.0.0.2
- IBM Watson Explorer Content Analytics Studio
- 12.0.0, 12.0.1, 12.0.2, 12.0.3, 11.0.0.0 – 11.0.0.3,
11.0.1.0 – 11.0.2.2
- 12.0.0, 12.0.1, 12.0.2, 12.0.3, 11.0.0.0 – 11.0.0.3,
The following fileset levels (VRMF) are vulnerable, if the respective Java version is installed:
- Java7: Less than 7.0.0.655
- Java7.1: Less than 7.1.0.455
- Java8: Less than 8.0.0.600
- AIX
- 7.2،7.1
- VIOS
- 2.2، 3.1
- AIX
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of Service (DoS)
- Obtain sensitive information remotely
- privilege elevation
- Execute arbitrary code
- Code Injection
- Bypass security restriction
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/support/pages/node/2801133
- https://www.ibm.com/support/pages/node/2801097
- https://www.ibm.com/support/pages/node/2801073
- https://www.ibm.com/support/pages/node/2801043
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-aix-2/
- https://www.ibm.com/support/pages/node/2800995
- https://www.ibm.com/support/pages/node/2801157
- https://www.ibm.com/support/pages/node/2440023
- https://www.ibm.com/support/pages/node/2800989
- https://www.ibm.com/support/pages/node/2801487
- https://www.ibm.com/support/pages/node/2801043