IBM Updates
2660Warning Date
Severity Level
Warning Number
Target Sector
21 October, 2020
● High
2020-1958
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- angular.js
- IBM Cloud Pak for Multicloud Management 2.0
- GO
- IBM Cloud Pak for Multicloud Management 2.0
- IBM Spectrum Scale V5.0.0.0 through V5.0.5.2, V4.2.0.0 through V4.2.3.23
- Node.js acorn and bootstrap-select
- IBM Cloud Pak for Multicloud Managementt 2.0
- BIND
- IBM i 7.4, 7.3, 7.2, 7.1
- IBM Spectrum Scale
- IBM Elastic Storage System 6.0.0 – 6.0.1.0
- IBM MQ 9.1 LTS, 9.0 LTS, 8.0, 9.1 CD
- IBM WebSphere MQ 7.5, 7.1
- GNU Binutils
- IBM Netezza Platform Software 4.6.8-4.6.12.P5, 5.0.10-5.2.2.P5, 6.0.3-6.1.P2, 7.0-7.2.1.10
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Bypass of a protection mechanism
- Cross-site scripting (XSS)
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-angular-js-affects-ibm-cloud-pak-for-multicloud-management-infrastructure-management-and-managed-service/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-go-affects-ibm-cloud-pak-for-multicloud-management-managed-service-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-has-been-identified-in-ibm-spectrum-scale-where-an-unprivileged-local-user-may-cause-a-denial-of-service-cve-2020-4411-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-node-js-acorn-and-bootstrap-select-affects-ibm-cloud-pak-for-multicloud-management-infrastructure-management-and-managed-service/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-go-affects-ibm-cloud-pak-for-multicloud-management-managed-service/
- https://www.ibm.com/blogs/psirt/security-bulletin-bind-for-ibm-i-is-affected-by-cve-2020-8622-and-cve-2020-8624/
- https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ibm-spectrum-scale-packaged-in-ibm-elastic-storage-system-could-cause-a-denial-of-service-cve-2020-4756-2/
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-could-allow-leak-sensitive-information-due-to-an-error-within-the-pre-v7-pubsub-logic-cve-2020-4319/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-gnu-binutils-affect-ibm-netezza-platform-software-clients-2/