IBM Alert
2926Warning Date
Severity Level
Warning Number
Target Sector
26 June, 2022
● High
2022-5002
All
IBM has released security updates to address several vulnerabilities in the following products:
- 7.3.0 – 7.3.3 Fix Pack 11
- QRadar / QRM / QVM / QRIF / QNI v7.4
- 7.4.0 – 7.4.3 Fix Pack 5
- QRadar / QRM / QVM / QRIF / QNI v7.5
- 7.5.0 – 7.5.0 Update Package 1
- IBM® DB2®
- IBM PureDaa System for Operational Analytics V1.1 (A1801)
- IBM Db2 V9.7, V10.1, V10.5, and V11.1
- IBM PureData System for Operational Analytics V1.1 (A1801)
- IBM Security Guardium
- 11.0
- 11.1
- 11.2
- 11.3
- 11.4
Attacker could exploit these vulnerabilities by doing the following:
- Obtain sensitive information
- Denial of service (DoS)
- Execute arbitrary code
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-siem-is-affected-by-a-remote-code-execution-in-spring-framework-cve-2022-22963-cve-2022-22965-cve-2022-22950/
- https://www.ibm.com/blogs/psirt/security-bulletin-one-or-more-security-vulnerabilities-has-been-identified-in-ibm-db2-shipped-with-ibm-puredata-system-for-operational-analytics-cve-2020-4230cve-2020-4135cve-2020-4204/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-cve-2019-10086-cve-2021-41617/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-22/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-multiple-vulnerabilities-21/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-db2-is-affected-by-multiple-vulnerabilities-due-to-the-consumed-expat-library/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-has-been-identified-in-ibm-db2-shipped-with-ibm-puredata-system-for-operational-analytics/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-is-affected-by-an-information-leak-vulnerability-within-kafka-cve-2021-38153/