IBM Updates
2765Warning Date
Severity Level
Warning Number
Target Sector
27 February, 2020
● Medium
2020-972
All
Description
IBM has released security updates to address multiple vulnerabilities in the following products:
- IBM Business Process Manager
- 8.5.7.0 - 8.5.7.0 2017.06
- 8.6.0.0 - 8.6.0.0 CF2018.03
- IBM Business Automation Workflow
- 18.0.0.1 - 19.0.0.3
- IBM MQ certified container
- 4.x.x CD
- IBM Tivoli System Automation Application Manager
- 4.1
IBM MobileFirst Platform Foundation
- 8.0.0.0 - ICP, IKS
- 7.1.0.0
- Using the scripts (BYOL) R7.5
- 87.52.x.x
- R8.4
- 88.4x.x.x
- R8.5
- 88.5x.x.x
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- SQL Injection.
- Denial of Service (DoS) remotely.
- Bypass Security restriction.
- Obtain sensitive information.
- Escalation of privilege
- Recover the Private Key.
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates: