This portal is to open public enhancement requests for IBM Sterling products and services. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).
We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:
Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,
Post an idea.
Get feedback from the IBM team and other customers to refine your idea.
Follow the idea through the IBM Ideas process.
Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.
IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.
ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.
Thank you for taking the time to provide your ideas to IBM. We truly value our relationship with you and appreciate your willingness to share details about your experience, your recommendations, and ideas.
IBM has evaluated the request and has determined that it cannot be implemented at this time or does not align with our current strategy or roadmap.
We adhere to IBM CISO's process, we are limited to what can be said and when. We cannot comment until a fix is available in every release available, hackers would check for unpatched older versions. Patches themselves could have 40+ fixes in every fixpack - an increasing number that makes it difficult to list in real-time and security is always evolving. We have a security section in release notes if it's been fixed across all solutions, otherwise we can't give details.
Each release updates the CVE DB (internal to IBM), but we don't make it public, even to business partners - CoE would have to ask for specifics. CISO controls what gets updated publicly for CVSS scores etc. In order to stay current on security, patches will need to be applied on a regular basis as best practice.
these days security vulnerability is no doubt the top priority on every customer's mind. Nobody wants their PROD environment attached by hackers or their names show up on yet another mass data leak news. IBM the s/w vendor should make the security patching mechanism as easy as possible, and as early as possible for every customer and their consultants to plug the holes.