IBM Updates
2600Warning Date
Severity Level
Warning Number
Target Sector
25 June, 2020
● Medium
2020-1403
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- ICP Speech to Text, Text to Speech – OpenSSL
- IBM QRadar Network
- IBM Bootable Media Creator (BoMC)
- IBM Maximo Asset Management
- ICP Speech to Text, Text to Speech Oracle Java
- Speech to Text, Text to Speech ICP, WebSphere Application Server Liberty
- IBM Watson Speech to Text, Text to Speech
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Buffer overflow
- Execute arbitrary code – remotely
- Unauthorized disclosure of information
- Denial of service attack (DoS)
- Spoofing attacks
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-icp-speech-to-text-text-to-speech-openssl-vulnerability-fix/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-qradar-network-security-is-affected-by-multiple-vulnerabilities/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-bootable-media-creator-bomc-is-affected-by-a-vulnerability-in-curl-cve-2019-5482/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-cross-site-scripting-cve-2020-4223/
- https://www.ibm.com/blogs/psirt/security-bulletin-icp-speech-to-text-text-to-speech-oracle-java-vulnerability-fix/
- https://www.ibm.com/blogs/psirt/security-bulletin-speech-to-text-text-to-speech-icp-websphere-application-server-liberty-fix-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-sql-injection-cve-2019-4650/
- https://www.ibm.com/blogs/psirt/security-bulletin-speech-to-text-text-to-speech-icp-websphere-application-server-liberty-fix-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-speech-to-text-text-to-speech-icp-websphere-application-server-liberty-fix-4/