IBM Support

Security Bulletin: Security vulnerability is addressed with IBM Cloud Pak for Business Automation iFixes for September 2022 (CVE-2021-2163)

Security Bulletin


Summary

In addition to many updates of operating system level packages, the following security vulnerability is addressed with IBM Cloud Pak for Business Automation 21.0.3-IF013 and 22.0.1-IF003.

Vulnerability Details

CVEID:   CVE-2021-2163
DESCRIPTION:   An unspecified vulnerability in Java SE related to the Libraries component could allow an unauthenticated attacker to cause no confidentiality impact, high integrity impact, and no availability impact.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/200292 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s) Status

IBM Cloud Pak for Business Automation

V22.0.1 - V22.0.1-IF002 affected
IBM Cloud Pak for Business Automation V21.0.3 - V21.0.3-IF012 affected
IBM Cloud Pak for Business Automation

V21.0.2 - V21.0.2-IF012 and later fixes
V21.0.1 - V21.0.1-IF007 and later fixes
V20.0.1 - V20.0.3 and later fixes
V19.0.1 - V19.0.3 and later fixes
V18.0.0 - V18.0.2 and later fixes

affected

Remediation/Fixes

Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components. The CVE in this bulletin are specifically addressed by
CVE ID Addressed in component
CVE-2021-2163 All Java based components
Affected Product(s) Version(s) Remediation / Fix
IBM Cloud Pak for Business Automation V22.0.1 Apply security fix 22.0.1-IF003
IBM Cloud Pak for Business Automation V21.0.3 - V21.0.3-IF010 Apply security fix 21.0.3-IF013 or upgrade to 22.0.1-IF003
IBM Cloud Pak for Business Automation V21.0.1 - V21.0.1-IF008
V20.0.1 - V20.0.3
V19.0.1 - V19.0.3
V18.0.0 - V18.0.2
Upgrade to 21.0.3-IF013 or 22.0.1-IF003

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

30 Sep 2022: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide


[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS2JQC","label":"IBM Cloud Pak for Automation"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"18.0.0, 18.0.1,18.0.2,19.0.1,19.0.2,19.0.3,20.0.1,20.0.2,20.0.3,21.0.1,21.0.2,21.0.3,22.0.1","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}},{"Type":"MASTER","Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBYVB","label":"IBM Cloud Pak for Business Automation"},"ARM Category":[{"code":"a8m3p000000LQWWAA4","label":"Operate"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"21.0.1;21.0.2;21.0.3;22.0.1"}]

Document Information

More support for:
IBM Cloud Pak for Automation

Software version:
18.0.0, 18.0.1,18.0.2,19.0.1,19.0.2,19.0.3,20.0.1,20.0.2,20.0.3,21.0.1,21.0.2,21.0.3,22.0.1

Document number:
6825499

Modified date:
30 September 2022

UID

ibm16825499

Manage My Notification Subscriptions