IBM Updates
2579Warning Date
Severity Level
Warning Number
Target Sector
25 August, 2021
● Critical
2021-3409
All
Description:
IBM has released a security updates to address multiple vulnerabilities in the following products:
- ITNCM
- 6.4.2
- ITNM
- 3.9
- 4.1.1.x
- 4.2.0.x
- IBM App Connect Enterprise
- V11
- V11.0.0.0 – V11.0.0.13
- IBM Integration Bus
- V10.0.0.0 – V10.0.0.23
- IBM App Connect Enterprise
- V12 12.0.1.0
- IBM DataPower Gateway V10 CD
- V10.0.2.0
- IBM DataPower Gateway 10.0.1
- 10.0.0.0-10.0.1.3
- IBM DataPower Gateway
- 2018.4.1.0-2018.4.1.16
- SDS VA
- 8.0.1
- Resilient OnPrem
- IBM Security SOAR
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of Service (DoS)
- Cross-site scripting (XSS)
- Obtain sensitive information
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-xstream-publicly-disclosed-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-apache-cxf-publicly-disclosed-vulnerability-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-xstream-publicly-disclosed-vulnerability-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-5/
- https://www.ibm.com/blogs/psirt/security-bulletin-update-secure-gateway-client-in-ibm-datapower-gateway-to-address-several-cves/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-security-vulnerabilities-have-been-identified-in-ibm-java-sdk-that-affect-ibm-security-directory-suite-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-resilient-disaster-recovery-dr-system-allows-connections-over-tls-1-0-cve-2021-29704/
- https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-14781-deferred-from-oracle-oct-2020-cpu-for-java-8/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-ibm-java-runtime-affect-ibm-integration-bus-and-ibm-app-connect-enterpise-v11-v12-cve-2020-27221-6/
- https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-2773-deferred-from-oracle-apr-2020-cpu-2/