Your review has been sent successfully

IBM Updates

2006
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

20 December, 2020

● High

2020-2237

All

Description:

IBM has released security updates to address vulnerabilities in the following products:

  • Version 12.18.0 of Node.js included in IBM Netcool Operations Insight 1.6.2.x
    • IBM Cloud Event Management on IBM Cloud Private
  • IBM Planning Analytics 2.0.9.4
  • z/Transaction Processing Facility 1.1
  • IBM Content Navigator 3.0CD
  • Datacap Taskmaster Capture 9.1.7
  • Financial Transaction Manager for Digital Payments for Multi-Platform 2.1.1, 3.0.0, 3.1.0, 3.2.3, 3.2.4, 3.0.2, 3.2.2, 3.0.5, 3.0.6
  • IBM Java Runtime
    • RDS 5.2.1 iFix 13 and earlier
    • RDA 6.0.0.2 iFix 06 and earlier
  • IBM Rational ClearCase 9.0, 9.0.1, 9.0.2
  • json-c
    • IBM MQ 9.1 LTS, 9.2 CD, 9.2 LTS
  • IBM MQ Appliance 9.2 CD, 9.2 LTS
  • IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.1 CD, 9.2 CD, 9.2 LTS
  • IBM WebSphere MQ 7.5
  • Pacemaker
    • IBM MQ 9.1 LTS, 9.1 CD, 9.2 CD, 9.2 LTS
  • IBM Cloud Pak for Automation 20.0.1, 20.0.2 IF002
  • BIND
    • AIX 7.1, 7.2
    • VIOS 3.1
  • IBM Cloud Pak for Automation IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 20.0.2
  • IBM Business Automation Workflow V18.0, V19.0, V20.0 traditional, V20.0 containers
  • IBM Business Process Manager V8.6

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Denial of service attack (DoS)
  • Cross-site scripting (XSS)
  • Sensitive information disclosure
  • Execute arbitrary code
  • Escalation of privilege

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 20 December, 2020

Rate the content

rate-icon
up icon