IBM Updates
2726Warning Date
Severity Level
Warning Number
Target Sector
29 July, 2020
● Medium
2020-1565
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM Netcool Configuration Manager 6.4.2
- Apache CXF
- IBM Tivoli Application Dependency Discovery Manager
- IBM Planning Analytics 2.0.0 – 2.0.9.1
- IBM Maximo Asset Management 7.6.0, 7.6.1
- IBM Security Key Lifecycle Manager 3.0.1, 4.0
- IBM® SDK Java™ Technology Edition, Version 7 ,version 8
- IBM Tivoli Composite Application Manager for Transactions
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Unauthorized disclosure of information
- Escalation of privilege
- Cross-site scripting (XSS)
- Bypass of a protection mechanism
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-sdk-java-technology-edition-quarterly-cpu-oct-2019-includes-oracle-oct-2019-cpu-affects-ibm-tivoli-composite-application-manager-for-transactions-robotic-response-time/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-security-key-lifecycle-manager/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-maximo-asset-management-is-vulnerable-to-information-disclosure-cve-2020-4463/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-planning-analytics-has-addressed-multiple-security-vulnerabilities-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-apache-cxf-vulnerability-identified-in-ibm-tivoli-application-dependency-discovery-manager-cve-2020-1954/
- https://www.ibm.com/blogs/psirt/security-bulletin-legacy-components-of-ibm-netcool-configuration-manager-have-been-updated/