Your review has been sent successfully

IBM Updates

2470
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

24 February, 2021

● Critical

2021-2523

All

Description:

IBM has released a security update to address several vulnerabilities in the following products:

  • OpenSSL
    • IBM WIoTP MessageGateway 5.0.0.1
  • Node.js
    • IBM Integration Bus V10.0.0 – V10.0.0.23
  • Node.js nodemailer module
    • IBM Cloud Pak for Multicloud Management Infrastructure Management
  • IBM Cloud Pak for Security 1.5.0.0, 1.5.0.0
  • OpenLDAP
    • MessageGateway
  • IBM MQ Appliance 9.1 LTS, 9.2 LTS, 9.1 CD
  • IBM Dependency Based Build server web UI
  • IBM Java Runtime
    • IBM WIoTP MessageGateway 5.0.0.1
    • IBM IoT MessageSight 5.0.0.0, 2.0.0.2
    • Integration Designer 8.5.7, 19.0.0.2, 20.0.0.1, 20.0.0.2

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Execute arbitrary commands -remotely
  • Denial of service attack (DoS)
  • Bypass of a protection mechanism -remotely

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 24 February, 2021

Rate the content

rate-icon
up icon