IBM Alert
9173Warning Date
Severity Level
Warning Number
Target Sector
24 August, 2022
● High
2022-5158
All
Description:
IBM has released security updates to address several vulnerabilities in several products:
- IBM Spectrum Discover
- IBM QRadar SIEM
- IBM Security Guardium Key Lifecycle Manager
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- Security Bulletin: IBM Spectrum Discover is vulnerable to multiple vulnerabilities - IBM PSIRT Blog
- Security Bulletin: IBM QRadar SIEM includes components with multiple known vulnerabilities - IBM PSIRT Blog
- Security Bulletin: Multiple security vulnerabilities have been identified in dojo library shipped with IBM Security Guardium Key Lifecycle Manager (SKLM/GKLM) (CVE-2019-10785, CVE-2020-5259, CVE-2020-4051, CVE-2018-15494, CVE-2021-23450) - IBM PSIRT Blog