Medium Severity

Security Bulletin: IBM Cloud Pak for Multicloud Management Monitoring is vulnerable to multiple security vulnerabilities due to its use of NodeJS (CVE-2021-22918, CVE-2021-22960, CVE-2021-22959)

Share this post:

NodeJS is used by multiple components of IBM Cloud Pak for Multicloud Management Monitoring as a runtime environment.

CVE(s): CVE-2021-22959, CVE-2021-22960, CVE-2021-22918

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Monitoring 2.0 – 2.3 Fix Pack 4

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6604049
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/211168
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/211171
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/204784

More stories

Security Bulletin: IBM MQ is affected by multiple vulnerabilities in IBM® Runtime Environment Java™ Technology Edition, Version 8

September 30, 2022 | Medium Severity

Multiple vulnerabilities were found with IBM® Runtime Environment Java™ Technology Edition, Version 8 which is shipped with IBM MQ and used for Java & JMS client, AMQP, MQTT, MFT & MQIPT functionality. ...read more


Security Bulletin: Vulnerability in the Node.js jose module affects IBM Event Streams (CVE-2022-36083)

September 30, 2022 | Medium Severity

This security vulnerability affects the Node.js jose module that is used by IBM Event Streams. ...read more


Security Bulletin: Due to use of IBM® SDK Java™ Technology Edition, IBM Virtualization Engine TS7700 is vulnerable to a data integrity threat (CVE-2022-21496)

September 30, 2022 | Medium Severity

IBM Virtualization Engine TS7700 is vulnerable to a data integrity threat (CVE-2022-21496) due to the use of IBM® SDK Java™ Technology Edition, Version 8. The SDK is used by the TS7700 to provide the Management Interface, to perform cache management, and to provide Transparent Cloud Tiering. This issue was disclosed as part of the IBM SDK Java Technology Edition update in April 2022. IBM Virtualization Engine TS7700 has addressed the applicable CVEs. ...read more