IBM Updates
2546Warning Date
Severity Level
Warning Number
Target Sector
9 July, 2020
● High
2020-1469
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- Netty
- IBM Security Guardium Insights
- IBM Java SDK and IBM Java Runtime
- Rational Business Developer
- IBM InfoSphere Information Server
- Kernel
- IBM Netezza Host Management
- IBM Watson Knowledge Catalog for IBM Cloud Pak for Data
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS) -remotely
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-security-guardium-insights-is-affected-by-a-netty-vulnerability-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-ibm-java-sdk-and-ibm-java-runtime-affects-rational-business-developer-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-infosphere-information-server-is-affected-by-a-remote-code-execution-vulnerability/
- https://www.ibm.com/blogs/psirt/security-bulletin-publicly-disclosed-vulnerability-from-kernel-affects-ibm-netezza-host-management/
- https://www.ibm.com/blogs/psirt/security-bulletin-missing-or-insecure-content-security-policy-header-affecting-watson-knowledge-catalog-for-ibm-cloud-pak-for-data/