Your review has been sent successfully

IBM Updates

2031
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

7 March, 2021

● High

2021-2579

All

Description:

IBM has released a security update to address several vulnerabilities in the following products:

  • Node.js
    • IBM App Connect Enterprise V11.0.0.0 – V11.0.0.11
    • IBM API Connect V10.0.1.1, V2018.4.1.0-2018.4.1.13
  • Apache Tomcat
    • IBM Tivoli Application Dependency Discovery Manager 7.3.0.0
  • libxslt
    • IBM MQ Appliance 9.1 LTS
    • IBM MQ Appliance 9.2 CD
    • IBM MQ Appliance 9.2 LTS
    • IBM MQ Appliance 9.1 CD
  • IBM InfoSphere Information Server 11.7, 11.5, 11.3
  • OpenSSL
    • IBM MQ Appliance 9.1 LTS
    • IBM MQ Appliance 9.2 CD
    • IBM MQ Appliance 9.2 LTS
    • IBM MQ Appliance 9.1 CD
  • Rational® Application Developer for WebSphere® Software 9.6, 9.7
  • libexpat
    • IBM MQ Appliance 9.1 LTS
    • IBM MQ Appliance 9.2 CD
    • IBM MQ Appliance 9.2 LTS
    • IBM MQ Appliance 9.1 CD
  • system
    • IBM MQ Appliance 9.1 LTS
    • IBM MQ Appliance 9.2 CD
    • IBM MQ Appliance 9.2 LTS
    • IBM MQ Appliance 9.1 CD
  • IBM WebSphere Application Server shipped with IBM StoredIQ for Legal 2.0.3
  • IBM Java Runtime
    • IBM Connect:Direct Web Services 6.0
    • Sterling Connect Direct Web Services 1.0
  • IBM Cloud Object Storage Systems 3.12.4.200, 3.13.6.166, 3.14.11.41
  • Python
    • IBM Watson Discovery for IBM Cloud Pak for Data
  • Google-api-client as used by IBM QRadar SIEM
  • IBM Content Navigator component in IBM Business Automation Workflow
  • IBM Java SDK
    • IBM WebSphere Application Server Patterns 1.0.0.0 through 1.0.0.7 and 2.2.0.0 through 2.3.3.3
    • IBM Tivoli System Automation Application Manager 4.1
  • jackson-databind
    • IBM Spectrum Symphony 7.3.1, 7.3, 7.2.1, 7.2.0.2
  • IBM Java SDK and IBM Java Runtime
    • TPF Toolkit 4.6, 4.2
  • Java SE
    • IBM API Connect V2018.4.1.0-2018.4.1.13
  • IBM API Connect V10, API Connect V10.0.1.1, V2018.4.1.0-2018.4.1.13

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Denial of service attack (DoS)
  • Sensitive information disclosure
  • Execute arbitrary code -remotely

Best practice and Recommendations:

The CERT team encourages users to review IBM security advisory and apply the necessary updates:

Last updated at 7 March, 2021

Rate the content

rate-icon
up icon