IBM Updates
2543Warning Date
Severity Level
Warning Number
Target Sector
6 August, 2020
● Medium
2020-1604
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM® SDK, Java™ Technology Edition
- 7.0.0.0 – 7.0.10.65
- 7.1.0.0 – 7.1.4.65
- 8.0.0.0 – 8.0.6.11
- IBM® Java SDK
- WebSphere Application Server Liberty Continuous delivery
- WebSphere Application Server 9.0
- WebSphere Application Server 8.5
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Unauthorized disclosure of information
- Unauthorized modification
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-may-affect-ibm-sdk-java-technology-edition-3/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-affect-websphere-application-server-july-2020-cpu-plus-deferred-cve-2020-2590-and-cve-2020-2601/
- https://www.ibm.com/blogs/psirt/security-bulletin-cve-2020-2590-may-affect-ibm-sdk-java-technology-edition/