IBM Alert
2651Warning Date
Severity Level
Warning Number
Target Sector
6 February, 2022
● High
2022-4334
All
Description:
IBM has released security updates to address several vulnerabilities in its products:
- App Connect Enterprise Certified Container
- 1.1-eus with Operator
- 1.5 with Operator
- 2.0 with Operator
- 2.1 with Operator
- 3.0 with Operator
- Netcool/OMNIbus
- 8.1.0
- GDE 5.0.0.2
- Guardium Data Encryption Server 5.0.0.2 (CipherTrust Manager 2.4.2)
- CM 2.4.2
- CM 2.4.2
- Guardium Data Encryption Server 5.0.0.2 (CipherTrust Manager 2.4.2)
Threats:
An attacker could exploit these vulnerabilities by:
- Obtain sensitive information
- Execute arbitrary code
- Denial of Service (DoS)
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-app-connect-for-healthcare-is-vulnerable-to-arbitrary-code-execution-due-to-apache-log4j-cve-2022-23302/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-insights-is-affected-by-multipe-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-app-connect-for-healthcare-is-vulnerable-to-arbitrary-code-execution-due-to-apache-log4j-cve-2022-23305/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-infosphere-information-server-is-vulnerable-to-arbitrary-code-execution-due-to-apache-log4j-cve-2021-44832/
- https://www.ibm.com/blogs/psirt/security-bulletin-liberty-for-java-for-ibm-cloud-is-vulnerable-to-ldap-injection-cve-2021-39031/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-apache-log4j-affect-ibm-tivoli-netcool-impact-cve-2021-45105-cve-2021-45046-4/
- https://www.ibm.com/blogs/psirt/security-bulletin-liberty-for-java-for-ibm-cloud-is-vulnerable-to-an-information-disclosure-cve-2022-22310/