High Severity
Potential CPU Security Issue
February 10, 2018
Categorized: High Severity
Share this post:
On Wednesday, January 3, researchers announced a security vulnerability impacting microprocessors. IBM is working with our clients and industry partners on this issue, which has the potential to affect many types of computing devices from different manufacturers. It’s important to note there are no known cases where this vulnerability has been used maliciously.
Patches will be made available for IBM systems via our normal customer portals. Further details concerning potentially impacted processors in the POWER family can be found here. Per our business as usual process, all information for IBM Z clients can be found at the IBM Z Portal.
IBM Storage appliances are not impacted by this vulnerability. For Storage, further details concerning this vulnerability can be found here.
Additional information will be provided through normal IBM communications channels, including IBM Security Bulletins. Please actively monitor both your IBM Support Portal and the IBM PSIRT Blog.
The most immediate action clients can take to protect themselves is to prevent execution of unauthorized software on any system that handles sensitive data, including adjacent virtual machines.
We will continue to update this blog to include additional information as appropriate.
Security Bulletin: Information Disclosure in IBM Spectrum Protect Operations Center Browser's History (CVE-2022-22484)
May 13, 2022 | Medium Severity
IBM Spectrum Protect Operations Center may disclose sensitive information in plain text in the brower's application command history. ...read more
Security Bulletin: IBM Planning Analytics Workspace is affected by multiple vulnerabilities (CVE-2022-22950, XFID:217968)
May 13, 2022 | Medium Severity
IBM Planning Analytics Workspace is affected by multiple vulnerabilites. Spring is used in IBM Planning Analytics Workspace in Server Side Rest APIs as an indirect dependency by MongoDB that is used to store content (CVE-2022-22950). FasterXML jackson-databind is used in IBM Planning Analytics Workspace to parse and generate json files (XFID: 217968). ...read more
Security Bulletin: AIX is vulnerable to a denial of service due to OpenSSL (CVE-2022-0778)
May 13, 2022 | High Severity
A vulnerability in OpenSSL could allow a remote attacker to cause a denial of service (CVE-2022-0778). OpenSSL is used by AIX as part of AIX's secure network communications. ...read more