Your review has been sent successfully

IBM Updates

2016
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

1 December, 2021

● High

2021-3954

All

Description:

IBM has released security updates to address several vulnerabilities in several products, mainly:

  • Apache CXF
    • IBM QRadar SIEM
  • OpenSSL
    • IBM Integration Bus and IBM App Connect Enterprise v11 & v12
  • Linux Kernel
    • IBM QRadar SIEM
  • Node.js
    • IBM Watson Discovery for IBM Cloud Pak for Data
    • IBM Integration Bus v10
  • Python Pillow
    • IBM Watson Discovery for IBM Cloud Pak for Data
  • IBM QRadar SIEM Application Framework Base Image
  • IBM HTTP Server (powered by Apache) for i
  • Apache Commons Compress
    • IBM Watson Discovery for IBM Cloud Pak for Data
  • IBM WebSphere Application Server used by IBM Match 360
  • Axios
    • IBM Watson Discovery for IBM Cloud Pak for Data
  • PostgreSQL as used by IBM QRadar SIEM

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service attack (DoS)
  • Unauthorized disclosure of information
  • Arbitrary code execution

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 1 December, 2021

Rate the content

rate-icon
up icon