Critical Severity

Security Bulletin: Vulnerabilities in XStream affect IBM Spectrum Copy Data Management

Share this post:

Vulnerabilities in XStream, such as execution of arbitrary code, server-side request forgery, denial of service, bypassing security restrictions, and deletion of arbitrary files, may affect IBM Spectrum Copy Data Management.

CVE(s): CVE-2020-26217, CVE-2021-39148, CVE-2021-21342, CVE-2021-21350, CVE-2021-21346, CVE-2021-21349, CVE-2021-21341, CVE-2021-21345, CVE-2021-21348, CVE-2021-21344, CVE-2021-21347, CVE-2021-21343, CVE-2021-21351, CVE-2021-39154, CVE-2021-39153, CVE-2021-39152, CVE-2021-39151, CVE-2021-39140, CVE-2021-39145, CVE-2021-39146, CVE-2021-39139, CVE-2021-39149, CVE-2021-39150, CVE-2021-39147, CVE-2021-39141, CVE-2021-29505, CVE-2020-26258, CVE-2020-26259, CVE-2021-39144

Affected product(s) and affected version(s):

Affected Product(s) Version(s)
IBM Spectrum Copy Data Management 2.2.13 and below

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/6525260
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/192210
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208116
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198619
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198627
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198623
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198626
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198618
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198622
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198625
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198621
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198624
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198620
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/198628
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208122
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208121
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208120
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208119
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208110
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208113
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208114
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208108
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208117
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208118
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208115
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208111
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/202795
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/193525
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/193524
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/208112

More stories

Security Bulletin: Multiple Vulnerabilities in jackson-databind shipped with IBM Cloud Pak System

August 12, 2022 | Critical Severity

Vulnerabilities identified in jackson-databind shipped with IBM Cloud Pak System. IBM Clous Pak System addresssed vulnerabilities. ...read more


Security Bulletin: Vulnerability in Apache Log4j affects IBM InfoSphere Master Data Management (CVE-2021-44228 )

August 12, 2022 | Critical Severity

There is a vulnerability in the Apache Log4j open source library used by IBM InfoSphere Master Data Management v11.6 and v12.0. ...read more


Security Bulletin: IBM Security Identity Manager Virtual Appliance is vulnerable to arbitrary code execution due to Apache Log4j and other issues (CVE-2021-4104, CVE-2021-45046, CVE-2021-38951)

August 12, 2022 | Critical Severity

IBM Security Identity Manager Virtual Appliance (ISIM VA) is vulnerable to arbitrary code execution due to Apache Log4j CVE-2021-4101 and CVE-2021-45046. Apache Log4j is used by ISIM VA as part of its logging infrastructure. This fix upgrades to Apache Log4j v2.17.1. IBM Security Identity Manager Virtual Appliance (ISIM VA) has also upgraded the other vulnerable components listed below. ...read more