IBM Patches Critical RCE Flaws in Data Virtualization Manager and Security SOAR
2024-11-27
Learn about the crucial role of timely patch management in preventing vulnerabilities and securing your clients' IT infrastructure.
IBM has released patches for several vulnerabilities in its products, including serious remote code execution issues in Data Virtualization Manager and Security SOAR. These vulnerabilities could allow attackers to execute arbitrary code or cause system disruptions. The company also addressed high-severity flaws in Watson Speech Services and OpenSSL, as well as various medium- and low-severity security issues in Engineering Lifecycle Management and other products. IBM has provided fix packs and guidance to mitigate these risks.
Patch Management, Web App/Website Vulnerability, Other: Prototype Pollution
IBM, RCE, Data Virtualization Manager, Security SOAR, Vulnerability, Patch Management, CVE-2024-52899, CVE-2024-45801
CVE-2024-52899; CVE-2024-45801; CVE-2024-49353; CVE-2024-6119
Data Virtualization Manager, Security SOAR, Watson Speech Services Cartridge for Cloud Pak for Data, OpenSSL, Engineering Lifecycle Management, IBM Workload Scheduler, Watson Query, Db2 Big SQL on Cloud Pak for Data
IBM has issued patches to address several vulnerabilities across its product suite, focusing on two high-severity remote code execution (RCE) flaws. These vulnerabilities, if exploited, could allow attackers to execute arbitrary code on affected systems, posing significant security risks. Resolution: IBM has released fix packs for versions 1.1 and 1.2 of the Data Virtualization Manager for z/OS. Detailed instructions for downloading and applying these fixes are provided in IBM's advisory. Security SOAR: Resolution: Patches have been released to address this issue. OpenSSL in Data Observability by Databand: IBM has also addressed several medium- and low-severity vulnerabilities in its Engineering Lifecycle Management tools. These issues could lead to cross-site scripting (XSS) attacks, unauthorized dashboard modifications, or the recovery of plaintext administrative credentials through network sniffing. Additionally, IBM Workload Scheduler was found to store user credentials in plaintext, and session expiration weaknesses in Watson Query and Db2 Big SQL on Cloud Pak for Data could expose sensitive information to authenticated attackers. IBM's proactive approach in issuing these patches highlights the importance of regular patch management in maintaining robust cybersecurity defenses. Users and administrators are encouraged to apply these updates promptly to safeguard their systems against potential exploits.IBM Patches Critical Vulnerabilities Across Multiple Products
Remote Code Execution Vulnerabilities
Object.prototype using specific payloads, leading to arbitrary code execution or denial-of-service conditions.Other High-Severity Vulnerabilities
Medium and Low-Severity Vulnerabilities