IBM Updates
2728Warning Date
Severity Level
Warning Number
Target Sector
11 February, 2020
● Medium
2020-899
All
Description:
IBM has released security updates to address vulnerabilities in the following products:
- IBM Content Navigator
- IBM Java Runtime
- IBM Platform Symphony
- IBM Spectrum Symphony
- IBM Java SDK
- IBM Decision Optimization Center (DOC)
- IBM Java Runtime
- IBM Decision Optimization Center (DOC)
- IBM ILOG CPLEX Optimization Studio (COS)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Server-side request forgery (SSRF)
- Denial of service attack (DoS)
- Sensitive information disclosure
- Take control of the system
Best practice and Recommendations:
The CERT team encourages users to review IBM security advisory and apply the necessary updates:
- https://www.ibm.com/blogs/psirt/security-bulletin-ibm-content-navigator-is-vulnerable-to-server-side-request-forgery-ssrf/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-ibm-platform-symphony-and-ibm-spectrum-symphony/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-sdk-and-ibm-java-runtime-affect-ibm-decision-optimization-center-cve-2020-2593-cve-2020-2583-cve-2019-4732/
- https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-in-ibm-java-runtime-affect-ibm-ilog-cplex-optimization-studio-and-ibm-cplex-enterprise-server-cve-2020-2593-cve-2020-2583-cve-2019-4732/