Your review has been sent successfully

IBM Updates

1892
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

21 October, 2021

● High

2021-3721

All

Description:

IBM has released a security update to address several vulnerabilities in its products, the most important ones:

  • IBM Event Streams 2018.3.0
  • IBM Event Streams CDR
  • IBM SAN Volume Controller
  • IBM Storwize V7000
  • IBM Storwize V5000
  • IBM Storwize V5100
  • IBM Storwize V3700
  • IBM Storwize V3500
  • IBM FlashSystem V9000
  • IBM FlashSystem 9100 Family
  • IBM FlashSystem 9200
  • IBM FlashSystem 7200
  • IBM FlashSystem 5200
  • IBM FlashSystem 5000
  • IBM Spectrum Virtualize Software
  • IBM Spectrum Virtualize for Public Cloud
  • QRadar Advisor 2.5 – QRadar Advisor 2.6.1
  • App Connect Enterprise Certified Container
    • 1.0 with Operator
    • 1.1 with Operator
    • 1.2 with Operator
    • 1.3 with Operator
    • 1.4 with Operator
    • 1.5 with Operator
    • 2.0 with Operator
  • IBM Cloud Pak System
    • V2.3.0.1, V.2.3.1.1, v.2.3.2.0
    • v2.3.3.0 v.2.3.3.1, v.2.3.3.2, v.2.3.3.3, v2.3.3.3 iFix 1
  • 9840-AE1 and 9843-AE1
  • 9840-AE2 and 9843-AE2
  • 9840-AE3 and 9843-AE3
  • App Connect Enterprise Certified Container
    • 2.0 with Operator
    • 1.5 with Operator
    • 1.4 with Operator
  • IBM Connect:Direct Web Services 6.0

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service (DoS)
  • Cross-site scripting (XSS)
  • Gain elevated privileges
  • Bypass security restrictions
  • Disclose sensitive information
  • Execute arbitrary code

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 21 October, 2021

Rate the content

rate-icon
up icon