IBM Alert
3027Warning Date
Severity Level
Warning Number
Target Sector
6 March, 2022
● Critical
2022-4481
All
Description:
IBM has released security updates to address several vulnerabilities in the following products, mainly:
- IBM Spectrum Control
- Sterling Connect:Direct Browser User Interface
- IBM® Security SOAR
- IBM Security QRadar SOAR
- IBM Cloud Pak for Business Automation
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Cross-site scripting (XSS) attack
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates, mainly:
- https://www.ibm.com/blogs/psirt/an-update-on-the-apache-log4j-cve-2021-44228-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-spectrum-control-is-vulnerable-to-multiple-weaknesses-related-to-ibm-dojo-cve-2021-234550-java-se-cve-2021-35578-ibm-websphere-application-server-liberty-cve-2021-39031/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-sterling-connectdirect-browser-user-interface/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-and-ibm-java-runtime-affect-ibm-security-qradar-soar-cve-2021-35560-cve-2021-35578-cve-2021-35564-cve-2021-35565-cve-2021-35588/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-qradar-soar-is-using-a-component-vulnerable-to-cross-site-scripting-cve-2021-41182-cve-2021-41183-cve-2021-41184/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerability-are-addressed-in-monthly-security-fix-for-ibm-cloud-pak-for-business-automation-february-2022/