IBM Updates
2502Warning Date
Severity Level
Warning Number
Target Sector
17 September, 2020
● High
2020-1792
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- WebSphere Application Server Liberty 17.0.0.3 – 20.0.0.9
- Aspera Shares 1.9.14 Patch Level 1
- WebSphere Application Server
- Cloud Orchestrator 2.5.0.10
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Sensitive information disclosure
- Denial of service attack (DoS)
- Execute arbitrary code -remotely
- Escalation of privilege
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-denial-of-service-vulnerability-in-websphere-application-server-liberty-cve-2020-4590/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-aspera-shares-1-9-14-patch-level-1-and-earlier-are-vulnerable-to-dom-xss-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-websphere-application-server-affect-ibm-cloud-orchestrator-and-ibm-cloud-orchestrator-enterprise/