IBM Updates
2643Warning Date
Severity Level
Warning Number
Target Sector
30 December, 2021
● Critical
2021-4150
All
IBM has released security updates to address Apache Log4j vulnerability in the following products:
- GDE (4.0.0.6) - Guardium Cloud Key Manager (GCKM) Appliance
- 1.10.0
- 1.10.1
- GDE (4.0.0.5) - Guardium Cloud Key Manager (GCKM) Appliance
- 1.9
- IBM Db2 V10.5
- V11.1
- V11.5
- IBM Db2 Web Query for i
- 2.3.0
- 2.2.1
Remote attacker could exploit this vulnerability by executing arbitrary code.
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-log4j-affects-ibm-guardium-data-encryption-gde-cve-2021-45105-and-cve-2021-45046/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-apache-log4j-affects-some-features-of-ibm-db2-cve-2021-4104-6/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-apache-log4j-affects-ibm-db2-web-query-for-i-cve-2021-45105/
For the latest updates on IBM products being affected by the Apache Log4j vulnerability: