IBM Updates
2640Warning Date
Severity Level
Warning Number
Target Sector
13 December, 2021
● Critical
2021-4032
All
Description:
IBM has released security updates to address several vulnerabilities in the following products:
- Rational Developer for i (RDi) RPG and COBOL + Modernization Tools, Java Edition
- WebSphere Application Server (Apache Log4j)
- 9.0
- 8.5
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Obtain sensitive information
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-node-js-affect-ibm-rational-application-developer-for-websphere-software-included-in-rational-developer-for-i/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-log4j-affects-websphere-application-server-cve-2021-44228/
For more information about IBM products being affected by the Apache Log4 vulnerability, please see the link below: