Rewterz

Rewterz Threat Alert – Trickbot IOCs

August 13, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-4662 – IBM Event Streams privilege escalation

August 17, 2020

Rewterz Threat Advisory – CVE-2020-4589 – IBM WebSphere Application Server code execution

Severity

High

Analysis Summary

IBM WebSphere Application Server could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. The vulnerability only occurs if an undocumented customization has been applied by an administrator.

Impact

Arbitrary code execution

Affected Vendors

IBM

Affected Products

  • IBM WebSphere Application Server 7.0
  • IBM WebSphere Application Server 8.0
  • IBM WebSphere Application Server 8.5
  • IBM WebSphere Application Server 9.0

Remediation

Refer to IBM Security Bulletin 6258333 for patch, upgrade or suggested workaround information. 

https://www.ibm.com/support/pages/node/6258333

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.