IBM Support

Security Bulletin: Vulnerabilities in OpenStack affect IBM Spectrum Scale V4.2 and V4.1.1 (CVE-2015-8466 and CVE-2016-0738)

Security Bulletin


Summary

OpenStack vulnerabilities that could allow:
- with OpenStack Swift 3, a remote attacker to launch a replay attack affects IBM Spectrum Scale (CVE-2015-8466)
- with OpenStack Object storage(Swift), a remote authenticated attacker could exploit this vulnerability to consume all available proxy-server resources (CVE-2016-0738)

Vulnerability Details


CVEID: CVE-2015-8466
DESCRIPTION: OpenStack Swift3 could allow a remote attacker to launch a replay attack. An attacker could exploit this vulnerability using an Authorization request that lacks a Date header to conduct a replay attack and gain unauthorized access to the device.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109647 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2016-0738
DESCRIPTION: OpenStack Object storage (Swift) is vulnerable to a denial of service, caused by a memory leak on an unfinished read. A remote authenticated attacker could exploit this vulnerability to consume all available proxy-server resources.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110091 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM Spectrum Scale V4.2.0.0 thru V4.2.0.2 and V4.1.1.0 thru 4.1.1.5 for Linux, Standard and Advanced Editions

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

23 May 2016: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"STXKQY","label":"IBM Spectrum Scale"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"}],"Version":"4.1.1;4.2.0","Edition":"Advanced;Standard","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
01 August 2018

UID

ssg1S1005833