IBM Updates
2676Warning Date
Severity Level
Warning Number
Target Sector
6 February, 2020
● Medium
2020-889
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- Embedded CF CLI
- IBM Cloud CLI
- Windows installers
- IBM Cloud CLI
- IBM Java Runtime
- IBM WIoTP MessageGateway
- IBM IoT MessageSight
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Unauthorized disclosure of information
- Take control of the system
- Denial of service attack (DoS)
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-of-embedded-cf-cli-in-ibm-cloud-cli/
- https://www.ibm.com/blogs/psirt/security-bulletin-windows-installers-of-ibm-cloud-cli-prior-to-0-16-2-are-signed-using-sha1-certificate/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-ibm-wiotp-messagegateway-cve-2020-2604-cve-2020-2659/