IBM Alert
2845Warning Date
Severity Level
Warning Number
Target Sector
23 January, 2022
● Critical
2022-4266
All
IBM has released a security update to address several vulnerabilities in its products, the most ones:
- IBM InfoSphere Information Server, Information Server on Cloud
- IBM Netcool Agile Service Manager
- IBM i
- IBM Cloud Pak for Data System 1.0 – Openshift Container Platform 3.11
- IBM Operational Decision Manager
- IBM Security Guardium
- IBM Operations Analytics Predictive Insights
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
- Denial of service attack (DoS)
The CERT team encourages users to review IBM security advisory and apply the necessary updates, the most ones:
- Security Bulletin: IBM InfoSphere Information Server is vulnerable to denial of service and arbitrary code execution due to Apache Log4j (CVE-2021-45105, CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Netcool Agile Service Manager is vulnerable to arbitrary code execution and denial of service due to Apache Log4j (CVE-2021-44832, CVE-2021-45046, CVE-2021-45105) - IBM PSIRT Blog
- Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime affect IBM i - IBM PSIRT Blog
- Security Bulletin: IBM QRadar hardware appliances are vulnerable to Intel privilege escalation (CVE-2021-0144) - IBM PSIRT Blog
- Security Bulletin: Log4j vulnerability CVE-2021-44228 affects IBM Cloud Pak for Data System 1.0 - IBM PSIRT Blog
- Security Bulletin: Vulnerability in Apache Log4j affects IBM Operational Decision Manager (CVE-2021-44228) - IBM PSIRT Blog
- Security Bulletin: IBM Security Guardium is vulnerable to a denial of service vulnerability in Apache log4j2 component (CVE-2021-45105 & CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Operations Analytics Predictive Insights is vulnerable to denial of service and arbitrary code execution due to Apache Log4j (CVE-2021-45105, CVE-2021-45046) - IBM PSIRT Blog
- Security Bulletin: IBM Cognos Controller has addressed multiple vulnerabilities - IBM PSIRT Blog