IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SKLM V3.01 vulnerabilities reported

    Posted 10/30/19 09:29 AM
      |   view attached

    Good day

     

    We have recently upgraded our customer from SKLM 2.07 to 3.01 and discovered that there are vulnerabilities reported for the DB2 version used within the build on both the previous and current build (details attached). Is there a different community for SKLM?

     

    "The vulnerability scan that ran last weekend identified a high-risk vulnerability on the version of DB2 that got installed with SKLM and also a medium risk vulnerability on the Websphere.

     

    Plugin Output:

      Installed version       : 11.1.2020.1393

      Path                    : D:\IBM\DB2SKLMV301\

      Instance                : SKLMDB31

      Product                 : DB2 Server

      Node                    : SRV007815

      Installed Special Build : None

      Fixed Special Build     : 38747

      Fixed version           : 11.1.4041.600"

     

    Regards

    017C440A-9B9A-44DD-A971-0D98F2361C4C@Dlink 

    Bruce Adams

    Business Development Specialist

    Excellenta (Pty) Ltd 

    Mobile: +27 82 449 9909 

    E-mail:  bruce@excellenta.co.za

    www.excellenta.co.za

     

    The information in this e-mail is confidential and intended solely for the addressee. Access to this e-mail by anyone else is unauthorised.

    Any copy or further distribution beyond the original recipient is not intended, and may be unlawful.

    The opinions enclosed are of those of the sender, and do not necessarily reflect those of Excellenta.

     

    Attachment(s)



  • 2.  RE: SKLM V3.01 vulnerabilities reported

    Posted 10/31/19 08:25 AM
    Hi Bruce,

    As there is no separate group for SKLM then this is the best discussion group to use for SKLM questions.  I will take this up with our Knowledge community team to see if we should change the name of this group or create a separate group for SKLM.

    With respect to your vulnerabilities I would recommend doing a web search for the specific CVEs identified.  This should provide you with more details such as: https://www.ibm.com/support/pages/security-bulletin-ibm-security-key-lifecycle-manager-uses-components-known-vulnerabilities-cve-2019-4322-cve-2019-4386-cve-2019-4154-cve-2019-4102-cve-2019-4101-cve-2019-4057

    Best regards

    Chris

    ------------------------------
    Chris BEANEY
    ------------------------------