Your review has been sent successfully

IBM Updates

2653
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

4 October, 2020

● High

2020-1874

All

Description:

IBM has released security updates to address vulnerabilities in the following products:

  • IBM Cloud Pak for Data – Golang
    • CP4D 2.5, 3.0
  • IBM Java SDK
    • IBM License Metric Tool
  • Apache Camel
    • IBM Resilient SOAR
  • IBM DB2 Server
    • IBM Emptoris Supplier Lifecycle Mgmt 10.1.3.x,10.1.1.x, 10.1.0.x
    • IBM Emptoris Program Management
    • IBM Emptoris Sourcing
    • IBM Emptoris Contract Management
    • IBM Emptoris Strategic Supply Management Platform 10.1.0.x,10.1.1.x,10.1.3.x
  • Plexus-utils
    • Resilient OnPrem IBM Security SOAR
  • Node.js npm CLI module
    • BM Cloud
  • WebSphere Application Server Liberty
    • IBM Operations Analytics – Log Analysis
  • Apache
    • Curam SPM 7.0.10, 7.0.9
  • IBM Maximo Asset Management 7.6.0, 7.6.1
  • App Connect Enterprise Certified Container 1.0.0 with Operator, 1.0.1 with Operator, 1.0.2 with Operator, 1.0.3 with Operator
  • Ruby on Rails
    • IBM License Metric Tool
  • Asset Repository in IBM Cloud Pak for Integration (CP4I) Operator 1.0.0, 1.0.1
  • Platform Navigator in IBM Cloud Pak for Integration (CP4I) Operator 4.0.0, 4.0.1
  • IBM Cloud Pak for Integration (CP4I) Operator 1.0.0

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Sensitive information disclosure
  • Denial of service attack (DoS)
  • Execute arbitrary code
  • Bypass of a protection mechanism

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 4 October, 2020

Rate the content

rate-icon
up icon