IBM Alert
23684Warning Date
Severity Level
Warning Number
Target Sector
10 August, 2022
● Critical
2022-5122
All
Description:
IBM has released security updates to address several vulnerabilities in several products:
- IBM Netezza for Cloud Pak for Data
- Automation Assets in IBM Cloud Pak for Integration
- IBM MQ Operator and Queue manager container images
- IBM Sterling Connect:Direct for Microsoft Windows
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Denial of service attack (DoS)
- Bypass of a protection mechanism
- Unauthorized disclosure of information
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-netezza-for-cloud-pak-for-data-is-vulnerable-to-denial-of-service-due-to-golang-net-package-cve-2021-33194/
- https://www.ibm.com/blogs/psirt/security-bulletin-automation-assets-in-ibm-cloud-pak-for-integration-is-vulnerable-to-denial-of-service-due-to-cve-2022-24434/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-operator-and-queue-manager-container-images-are-vulnerable-to-multiple-vulnerabilities-from-golang-go-libxml2-curl-expat-libgcrypt-and-ibm-websphere-application-server-li/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-for-microsoft-windows-is-vulnerable-to-an-unspecified-vulnerability-due-to-google-gson-cve-2022-25647/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-netezza-for-cloud-pak-for-data-is-vulnerable-to-cve-2022-0811/