Your review has been sent successfully

IBM Updates

1870
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

13 December, 2020

● High

2020-2193

All

Description:

IBM has released security updates to address several vulnerabilities in the following products:

  • IBM Cloud Pak for Data – Python 2.5, 3.0
  • NGINX vulnerability
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
  • cURL
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
    • IBM Aspera Streaming / IBM Aspera Streaming for Video 3.9.6.1 and earlier
  • HAProxy
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
  • IBM® Db2® V9.7, V10.1, V10.5, V11.1, and V11.5
  • NGINX
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
  • BM Java Runtime
    • IBM App Connect Enterprise V11 , V11.0.0.0 – V11.0.0.10
  • HAProxy
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
  • App Connect Enterprise Certified Container Integration Servers
    • App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5
  • AWS storage layer in NPS
    • IBM Netezza for Cloud Pak for Data
  • OpenSSL
    • IBM Aspera Streaming / IBM Aspera Streaming for Video 3.9.6.1 and earlier
    • IBM Aspera High-Speed Transfer Server 3.9.6.2 and earlier
    • IBM Aspera High-Speed Transfer Endpoint 3.9.6.2 and earlier
    • IBM Aspera Desktop Client 3.9.6 and earlier
    • IBM Aspera Connect 3.9.9 and earlier
    • App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6 with Operator
  • CP4D
    • IBM Netezza for Cloud Pak for Data
  • Resilient OnPrem IBM Security SOAR
  • IBM Elastic Storage System GUI 6.0.1.0, 5.36
  • NPS softlayer provisioner
    • IBM Netezza for Cloud Pak for Data
  • IBM SDK, Java Technology Edition Quarterly CPU – Jul 2020
    • InfoSphere Streams 4.3.1.x, 4.2.1.x, 4.1.1.x
  • glibc
    • IBM Elastic Storage System 6.0.0 – 6.0.1.1
  • WebSphere Application Server Liberty
    • IBM Cloud Transformation Advisor 2.3.0, 2.3.1
  • Node.js
    • IBM Cloud Transformation Advisor 2.3.0, 2.3.1
    • IBM Business Automation Workflow V20.0, V19.0, V18.0
    • IBM Business Process Manager V8.6, V8.5
  • IBM Spectrum Scale
    • IBM Elastic Storage Server 5.3.0 through ESS 5.3.6, 5.0.0 through ESS 5.2.10
  • Linux Kernel
    • IBM Elastic Storage System 6.0.0 – 6.0.1.1
  • Java
    • InfoSphere Streams 4.2.1.x, 4.3.1.x
  • IBM MQ for HPE NonStop 8.1.0, 8.0.4
  • IBM Java SDK
    • IBM WebSphere Application Server Patterns 1.0.0.0 through 1.0.0.7 and 2.2.0.0 through 2.3.3.3.
  • Apache Hadoop
    • InfoSphere Streams 4.2.1.x, 4.3.1,x
  • Apache Commons Codec
    • InfoSphere Streams 4.2.1.x, 4.3.1,x
  • GNU glibc
    • IBM Cloud Pak for Data 3.0
  • IBM Java Runtime
    • IBM Security SiteProtector System 3.0.0, 3.1.1

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Code injection
  • Sensitive information disclosure
  • Man in the middle attack
  • Buffer overflow
  • Denial of service attack (DoS)
  • Escalation of privilege

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 13 December, 2020

Rate the content

rate-icon
up icon