IBM Alert
2719Warning Date
Severity Level
Warning Number
Target Sector
22 June, 2022
● Medium
2022-4992
All
Description:
IBM has released security updates to address several vulnerabilities in the following products, mainly:
- DataPower Operator 1.2 1.2.0-1.2.6
- DataPower Operator 1.5 1.5.0
- IBM DataPower Gateway V10CD
- 10.0.2.0-10.0.4.0
- IBM DataPower Gateway
- 10.0.1 10.0.1.0-10.0.1.5
- IBM DataPower Gateway 2018.4.1
- 2018.4.1.0-2018.4.1.18
- IBM Spectrum Conductor 2.4.1
- IBM Spectrum Conductor 2.5.0
- IBM Spectrum Conductor 2.5.1
- IBM Spectrum Symphony
- 7.3
- 7.3.1
- 7.3.2
- IBM Cloud Pak for Business Automation
- V21.0.3 – V21.0.3-IF008
- V21.0.2 – V21.0.2-IF010
- V21.0.1 – V21.0.1-IF007
- V20.0.1 – V20.0.3
- V19.0.1 – V19.0.3
- V18.0.0 – V18.0.2
- IBM Security Guardium
- 10.5
- 10.6
- 11.0
- 11.1
- 11.2
- 11.3
- 11.4
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Obtain sensitive information
- Denial of service (DoS)
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates, mainly:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-browser-user-interface-has-multiple-vulnerabilities-due-to-ibm-java/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-ftp-is-vulnerable-to-unauthorized-data-access-due-to-ibm-java-cve-2021-35550/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affects-ibm-websphere-application-server-january-2022-cpu-that-is-bundled-with-ibm-websphere-application-server-patterns/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-file-agent-is-vulnerable-to-an-unspecified-vulnerability-due-to-ibm-java-runtime-cve-2021-35550/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-spring-framework-affects-ibm-watson-explorer-cve-2022-22971-cve-2022-22968-cve-2022-22970/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-ftp-is-vulnerable-to-unauthorized-sensitive-information-access-due-to-ibm-java-vulnerability-cve-2021-35603/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-websphere-application-server-and-websphere-application-server-liberty-affect-ibm-watson-explorer-cve-2022-22475-cve-2021-39038/
- https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerability-has-been-identified-in-ibm-db2-used-by-ibm-security-verify-governance-identity-manager-virtual-appliance-component/
- https://www.ibm.com/blogs/psirt/security-bulletin-rational-team-concert-rtc-and-ibm-engineering-workflow-management-ewm-openssl-vulnerability-cve-2021-4044/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-file-agent-is-vulnerable-to-an-unspecified-vulnerability-due-to-ibm-java-runtime-cve-2021-35603/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-cve-2021-35550-in-ibm-java-runtime-affects-cics-transaction-gateway/
- https://www.ibm.com/blogs/psirt/security-bulletin-june-2022-multiple-vulnerabilities-in-ibm-java-runtime-affect-cics-transaction-gateway/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sdk-java-technology-edition-quarterly-cpu-jan-2022-includes-oracle-january-2022-cpu-affects-ibm-tivoli-composite-application-manager-for-transactions-robotic-response/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-openssl-affects-ibm-watson-explorer-cve-2022-0778/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sterling-connectdirect-browser-user-interface-is-vulnerable-to-multiple-vulnerabilities-due-to-jetty/