IBM Alert
2899Warning Date
Severity Level
Warning Number
Target Sector
9 August, 2022
● High
2022-5107
All
IBM has released security updates to address several vulnerabilities in several products:
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- IBM Workload Scheduler
- IBM Cloud Pak System
- IBM Security SiteProtector System
- IBM Voice Gateway
- BM Netezza for Cloud Pak for Data
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Denial of service attack (DoS)
- Bypass of a protection mechanism
- Unauthorized disclosure of information
- Cross-site scripting (XSS)
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-platform-navigator-and-automation-assets-in-ibm-cloud-pak-for-integration-are-vulnerable-to-denial-of-service-due-to-go-cve-2021-43565/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-workload-scheduler-is-potentially-vulnerable-to-denial-of-service-due-to-cve-2022-0778-affecting-openssl-component/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-spring-framework-affect-ibm-cloud-pak-system-cve-2022-22965-cve-2020-5421/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-siteprotector-system-is-affected-by-multiple-apache-http-server-vulnerabilities-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-platform-navigator-and-automation-assets-in-ibm-cloud-pak-for-integration-are-vulnerable-to-denial-of-service-due-to-openssl-cve-2022-0778/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-node-js-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-netezza-for-cloud-pak-for-data-is-vulnerable-to-denial-of-service-due-to-golang-net-package-cve-2021-27918-cve-2021-44716-cve-2021-31525/
- https://www.ibm.com/blogs/psirt/security-bulletin-platform-navigator-and-automation-assets-in-ibm-cloud-pak-for-integration-are-vulnerable-to-denial-of-service-due-to-go-cve-2021-38561/