IBM Alert
2654Warning Date
Severity Level
Warning Number
Target Sector
30 April, 2022
● High
2022-4755
All
IBM has released security updates to address several vulnerabilities in the following products:
- APM AM
- 8.1.4
- APM SaaS
- 8.1.4
- APM on-premise
- 8.1.4
- IBM Cloud Pak for Business Automation
- V21.0.3 – V21.0.3-IF008
- V21.0.2 – V21.0.2-IF009
- V21.0.1 – V21.0.1-IF007
- V20.0.1 – V20.0.3
- V19.0.1 – V19.0.3
- V18.0.0 – V18.0.2
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- 4.0.0 – 4.0.7
- Integration Designer
- 21.0.3
- 21.0.2
- 20.0.0.2
- 19.0.0.2
- 8.5.7
Remote attacker could exploit these vulnerabilities by doing the following:
- Denial of Service (DoS) attack
- Obtain sensitive information
- Cross-site scripting (XSS)
- Arbitrary code execution
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-of-mozilla-firefox-less-than-firefox-91-8-0esr-have-affected-synthetic-playback-agent-8-1-4-0-8-1-4-if16-2022-4-0/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-are-addressed-with-ibm-cloud-pak-for-business-automation-ifixes-for-april-2022/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-speech-services-cartridge-for-ibm-cloud-pak-for-data-is-vulnerable-to-a-buffer-overflow-and-underflow-in-gnu-c-library-cve-2021-3999/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-speech-services-cartridge-for-ibm-cloud-pak-for-data-is-vulnerable-to-a-stack-based-buffer-overflow-in-gnu-c-library-cve-2022-23218/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-integration-designer-is-vulnerable-to-arbitrary-code-execution-because-of-apache-log4j-cve-2021-4104-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-speech-services-cartridge-for-ibm-cloud-pak-for-data-is-vulnerable-to-stack-based-buffer-overflow-in-gnu-c-library-cve-2022-23219/