IBM Alert
2901Warning Date
Severity Level
Warning Number
Target Sector
27 July, 2022
● Critical
2022-5074
All
IBM has released security updates to address several vulnerabilities in the following products, mainly:
- IBM Rational ClearQuest
- IBM Cloud Pak for Business Automation
- IBM QRadar SIEM
- IBM App Connect Enterprise
- IBM Integration Bus
- Rational Quality Manager (RQM)
- Engineering Test Management (ETM)
- ETM
- RQM
- Manage Component
- IBM Maximo Application Suite as a Service
- IBM Maximo Asset Management
- IBM System Dashboard for Enterprise Content Management
An attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Denial of service (DoS)
- Elevate privileges
- Bypass security restrictions
The CERT team encourages users to review IBM security advisory and apply the necessary updates, mainly:
- Security Bulletin: Multiple vulnerabilities in the IBM Java Runtime affect IBM Rational ClearQuest (CVE-2021-35561, CVE-2022-21299, CVE-2022-21496) - IBM PSIRT Blog
- Security Bulletin: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for June 2022 - IBM PSIRT Blog
- Security Bulletin: IBM QRadar SIEM is vulnerable to local privilege escalation (CVE-2021-39088) - IBM PSIRT Blog
- Security Bulletin: IBM QRadar SIEM Application Framework Base Image is vulnerable to using components with Known Vulnerabilities - IBM PSIRT Blog
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-integration-bus-and-ibm-app-connect-enterprise-are-vulnerable-to-a-denial-of-service-due-to-jackson-databind-cve-2020-36518/
- Security Bulletin: Multiple vulnerabilites affect IBM Engineering Test Management product due to XStream - IBM PSIRT Blog
- Security Bulletin: IBM Maximo Asset Management, IBM Maximo Manage in IBM Maximo Application Suite and IBM Maximo Manage in IBM Maximo Application Suite as a Service may be affected by XML External Entity (XXE) attacks (CVE-2021-33813) - IBM PSIRT Blog
- Security Bulletin: Apache Derby security vulnerabilities in IBM System Dashboard for Enterprise Content Manager (affected, not vulnerable) - IBM PSIRT Blog