Tuesday, June 30, 2020

Security Bulletin: Rational Asset Analyzer is affected by a vulnerability in Websphere Application Server.

Jun 30, 2020 8:03 pm EDT

Categorized: High Severity

Share this post:

IBM WebSphere Application Server used by Rational Asset Analyzer is vulnerable to a denial of service, caused by sending a specially-crafted request. .

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
Asset Analyzer (RAA) 6.1.0.0 – 6.1.0.23

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242308



from IBM Product Security Incident Response Team https://ift.tt/2BpCZDr

Security Bulletin: IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers.

Jun 30, 2020 8:03 pm EDT

Categorized: Medium Severity

Share this post:

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handling of request headers. A remote attacker could exploit this vulnerability to cause the consumption of Memory. IBM X-Force ID: 156242.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
InfoSphere Streams 4.3.1.x
InfoSphere Streams 4.2.1.x
InfoSphere Streams 4.1.1.x

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242192



from IBM Product Security Incident Response Team https://ift.tt/3dPXuq1

Security Bulletin: IBM® Db2® is vulnerable to an information disclosure. (CVE-2020-4386)

Jun 30, 2020 8:03 pm EDT

Categorized: Medium Severity

Share this post:

IBM® Db2® could allow a local user to obtain sensitive information using a race condition of a symbolic link.

Affected product(s) and affected version(s):

All fix pack levels of IBM Db2 V9.7, V10.1, V10.5, V11.1, and V11.5 editions on all platforms are affected.

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242342



from IBM Product Security Incident Response Team https://ift.tt/2ZmuCRa

Security Bulletin: IBM MQ for HPE NonStop Server is affected by vulnerability CVE-2020-4376

IBM MQ for HPE NonStop Server is affected by vulnerability CVE-2020-4376

Affected product(s) and affected version(s):

 Affected Product(s)  Version(s)
 IBM MQ for HPE NonStop  8.1.0
 IBM MQ for HPE NonStop  8.0.4

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242364

The post Security Bulletin: IBM MQ for HPE NonStop Server is affected by vulnerability CVE-2020-4376 appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/3gb2Ttp

Security Bulletin: Potential vulnerability (SSRF) in Apache Solr affect IBM Operations Analytics – Log Analysis (CVE-2017-3164)

Jun 30, 2020 8:03 pm EDT

Categorized: Medium Severity

Share this post:

Server Side Request Forgery vulnerability in Apache Solr could allow attacker with access to make Solr perform a HTTP to any reachable URL.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
Log Analysis 1.3.1
Log Analysis 1.3.2
Log Analysis 1.3.3
Log Analysis 1.3.4
Log Analysis 1.3.5
Log Analysis 1.3.6

 

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242160



from IBM Product Security Incident Response Team https://ift.tt/3eRp7R0

Security Bulletin: Host Header Injection vulnerability in IBM Operations Analytics – Log Analysis (pre-login scenario)

Jun 30, 2020 8:02 pm EDT

Categorized: Medium Severity

Share this post:

HTTP Host header value is use to generate links, import scripts and generate password resets. The value can be controlled by attacker and be exploited using web-cache poisoning and alternative channels. In Log Analysis, host header injection can be exploited to run scripts in the context of the application by remote file inclusion in particular pre-login scenario.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
Log Analysis 1.3.1
Log Analysis 1.3.2
Log Analysis 1.3.3
Log Analysis 1.3.4
Log Analysis 1.3.5
Log Analysis 1.3.6

 

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242210



from IBM Product Security Incident Response Team https://ift.tt/2Agrwp4

Security Bulletin: A security vulnerabilities has been identified in WebSphere Liberty Profile shipped with IBM License Metric Tool v9 .

Cross-site scripting vulnerabilities has been identified in WebSphere Liberty Profile leading to potential credentials disclosure.

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM License Metric Tool All

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6242108

The post Security Bulletin: A security vulnerabilities has been identified in WebSphere Liberty Profile shipped with IBM License Metric Tool v9 . appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/38gEpMt