Critical Severity

Security Bulletin: Multiple vulnerabilities in VMware affect IBM Cloud Pak System

Share this post:

Multiple vulnerabilities have been identified in VMware, a supporting product shipped with IBM Cloud Pak System. Vulnerabilities in VMware vSphere Client (HTML5) for VMware vCenter plugins in vRealize Operations Environment, not used in Cloud Pak Systems, but for VMware vulnerabile vCenter endpoints exist. The recommendation is to apply workaround. Refer to the corresponding sections below for details.

CVE(s): CVE-2021-21972, CVE-2021-21973

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Cloud Pak System 2.3.x.x

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin:
X-Force Database:
X-Force Database:

More stories

Security Bulletin: Multiple vulnerabilities affect IBM Rational® Application Developer for WebSphere® Software – September 2021

Oct 25, 2021 8:00 pm EDT | Critical Severity

Vulnerabilities detected in Node.js versions before v14.16.2 affects IBM Rational® Application Developer for WebSphere® Software. more

Security Bulletin: Vulnerabilities affect Watson Explorer Foundational Components (CVE-2021-3712, CVE-2021-3711)

Oct 22, 2021 8:03 pm EDT | Critical Severity

A critical OpenSSL buffer overflow vulnerability and possible denial of service affect IBM Watson Explorer Foundational Components. IBM Watson Explorer Foundational Components has addressed the vulnerabilities by updating the version of OpenSSL. more

Security Bulletin: IBM QRadar Advisor With Watson uses components with known vulnerabilities (CVE-2020-36242, CVE-2021-33503, CVE-2020-28493)

Oct 20, 2021 8:02 pm EDT | Critical Severity

The product includes vulnerable components (e.g., framework libraries) that may be identified and exploited with automated tools. This update addresses these vulnerabilities. more