IBM Updates
2477Warning Date
Severity Level
Warning Number
Target Sector
23 July, 2021
● Medium
2021-3247
All
Description:
IBM has released security updates to address several vulnerabilities in the following products:
- IBM Emptoris Supplier Lifecycle Mgmt
- 10.1.1.x
- 10.1.0.x
- 10.1.3.x
- IBM Integration Bus
- V10.0.0 – V10.0.0.23 (Linux x86-64 and Windows x86-64 only)
- IBM App connect Enterprise
- V11 , V11.0.0.0 – V11.0.0.12
- IBM Emptoris Program Management
- 10.1.1.x
- 10.1.0.x
- 10.1.3.x
- IBM Emptoris Strategic Supply Management Platform
- 10.1.1.x
- 10.1.0.x
- 10.1.3.x
- IBM Emptoris Sourcing
- IBM Emptoris Sourcing 10.1.0.x
- 10.1.1.x
- IBM Emptoris Sourcing 10.1.3.x
- SDS
- 6.4.0
- InfoSphere Information Server
- 11.7
- ITCAM for Transactions
- 7.4.0.1 and 7.4.0.2
- IBM Netezza Host Management
- starting 5.4.9.0
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS)
- Obtain sensitive information
- Bypass security restrictions
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/support/pages/node/6474467
- https://www.ibm.com/support/pages/node/6467639
- https://www.ibm.com/support/pages/node/6474461
- https://www.ibm.com/support/pages/node/6474455
- https://www.ibm.com/support/pages/node/6474475
- https://www.ibm.com/support/pages/node/6474463
- https://www.ibm.com/support/pages/node/6474465
- https://www.ibm.com/support/pages/node/6474233
- https://www.ibm.com/support/pages/node/6468569
- https://www.ibm.com/support/pages/node/6468569
- https://www.ibm.com/support/pages/node/6474245
- https://www.ibm.com/support/pages/node/6474223