Critical Severity

Security Bulletin: Vulnerabilities in the Python, Python cryptography , and Urllib3 affect IBM Spectrum Discover.

Share this post:

Vulnerabilities in Python, Python cryptography , and Urllib3 such as buffering problems, SSL certificate validations for HTTP & HTTPS, Bleichenbacher timing attacks in the RSA decryption API, may affect IBM Spectrum Discover.

CVE(s): CVE-2020-36242, CVE-2020-25659, CVE-2021-28363, CVE-2021-3177

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
Spectrum Discover 2.0.3
Spectrum Discover 2.0.3.1
Spectrum Discover 2.0.3.2
Spectrum Discover 2.0.3.3
Spectrum Discover 2.0.3.4
Spectrum Discover 2.0.4
Spectrum Discover 2.0.4.1

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6469481
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/196426
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/192485
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198199
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/195244

More stories

Security Bulletin: Due to use of Apache Log4j, IBM Robotic Process Automation with Automation Anywhere is vulnerable to arbitrary code execution (CVE-2021-45046) and denial of service (CVE-2021-45105)

Jan 16, 2022 7:00 pm EST | Critical Severity

There are vulnerabilities in the Apache Log4j library used by IBM Robotic Process Automation with Automation Anywhere. This affects the IBM Robotic Process Automation with Automation Anywhere control room application. This vulnerability has been addressed by upgrading the Apache Log4j library to version 2.17.0. ...read more


Security Bulletin: IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in Apache Log4j

Jan 16, 2022 7:00 pm EST | Critical Severity

IBM Watson Discovery for IBM Cloud Pak for Data contains a vulnerable version of Apache Log4j. ...read more


Security Bulletin: Vulnerability in Apache Log4j affects IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments (CVE-2021-44228)

Jan 16, 2022 6:19 pm EST | Critical Severity

A vulnerability in Apache Log4j could allow an attacker to execute arbitrary code on the system. This vulnerability may affect the IBM Spectrum Protect Client Web GUI and IBM Spectrum Protect for Virtual Environments due to their uses of Log4j for logging of messages and traces. ...read more