IBM Alert
2655Warning Date
Severity Level
Warning Number
Target Sector
3 May, 2022
● High
2022-4765
All
IBM has released security updates to address several vulnerabilities in the following products:
- IBM Spectrum Scale
- 5.1.0 – 5.1.3.0
- IBM Tivoli Monitoring
- 6.3.0 - 6.3.0.7
- IBM Cloud Pak System
- V2.3
- V2.3.1.1
- V2.3.2.0
- v2.3.3.1
- V2.3.3.2
- V2.3.3.3
- V2.3.3.3 ifix1
- BM Maximo Asset Management
- 7.6.1.1
- 7.6.1.2
- Maximo Manage Application in IBM Maximo Application Suite
- MAS 8.7-Manage 8.3
- IBM MaaS360 Mobile Enterprise Gateway module
- 2.106.200 and prior
- IBM MaaS360 Cloud Extender Configuration Utility module
- 2.105.200 and prior
An attacker could exploit these vulnerabilities by doing the following:
- Decrypt highly sensitive information
- Gain elevated privileges
- Cross-site scripting (XSS)
- Arbitrary code execution
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-has-been-identified-in-ibm-spectrum-scale-that-could-allow-an-attacker-to-decrypt-highly-sensitive-informationcve-2022-22368/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-websphere-application-server-liberty-affects-ibm-spectrum-scale-cve-2021-39031/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-java-included-with-ibm-tivoli-monitoring-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-intel-xeon-affects-ibm-cloud-pak-system-cve-2021-0144-4/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-tivoli-monitoring-is-affected-but-not-classified-as-vulnerable-by-a-denial-of-service-in-spring-framework-cve-2022-22950/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-websphere-application-server-liberty-affects-ibm-spectrum-scale-cve-2021-39038/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maximo-asset-management-and-the-ibm-maximo-manage-application-in-ibm-maximo-application-suite-are-vulnerable-to-host-header-injection-cve-2021-29854/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-java-jdk-affects-ibm-spectrum-scale-cve-2022-21291/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maas360-cloud-extender-configuration-utility-and-mobile-enterprise-gateway-have-vulnerability-cve-2021-43797