IBM Support

Security Bulletin: Multiple vulnerabilities in IBM WebSphere Application Server affect Cloud Pak System

Security Bulletin


Summary

Multiple vulnerabilities have been identified in IBM WebSphere Application Server, a supporting product which is shipped as pattern type with Cloud Pak System. This Security bulletin applies to Cloud Pak System Software and Cloud Pak System Software Suite.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)Affected Supporting Product Version(s)
IBM Cloud Pak System Software Suite 2.3.3.0WebSphere Application Server 9.0
IBM Cloud Pak System2.3WebSphere Application Server 9.0

Remediation/Fixes

Consult Security Bulletin WebSphere Application Server (WAS) https://www.ibm.com/support/pages/node/6540288 for vulnerability details and information about fixes. IBM strongly recommends to apply fix as soon as practical.  

In order to apply the fix

1.  Download the fix from IBM FixCentral

2.  Upload the fix to Cloud Pak System

3.  Apply the fix from CPS UI select WAS virtual system instance, manage,  operations and fixpack, or through the command line.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

23 Mar 2022: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU025","label":"IBM Cloud and Cognitive Software"},"Product":{"code":"SSFQWQ","label":"IBM Cloud Pak System"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.3","Edition":""}]

Document Information

Modified date:
06 May 2022

Initial Publish date:
23 March 2022

UID

ibm16570927