Security Bulletin
Summary
OpenStack vulnerabilities that could allow:
- with OpenStack Swift 3, a remote attacker to launch a replay attack affects IBM Spectrum Scale (CVE-2015-8466)
- with OpenStack Object storage(Swift), a remote authenticated attacker could exploit this vulnerability to consume all available proxy-server resources (CVE-2016-0738)
Vulnerability Details
CVEID: CVE-2015-8466
DESCRIPTION: OpenStack Swift3 could allow a remote attacker to launch a replay attack. An attacker could exploit this vulnerability using an Authorization request that lacks a Date header to conduct a replay attack and gain unauthorized access to the device.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/109647 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CVEID: CVE-2016-0738
DESCRIPTION: OpenStack Object storage (Swift) is vulnerable to a denial of service, caused by a memory leak on an unfinished read. A remote authenticated attacker could exploit this vulnerability to consume all available proxy-server resources.
CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110091 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Affected Products and Versions
IBM Spectrum Scale V4.2.0.0 thru V4.2.0.2 and V4.1.1.0 thru 4.1.1.5 for Linux, Standard and Advanced Editions
Remediation/Fixes
For IBM Spectrum Scale V4.2.0.0 thru V4.2.0.2, apply IBM Spectrum Scale V4.2.0.3 available from Fix Central at
http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%2Bdefined%2Bstorage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.2.0&platform=All&function=all
For IBM Spectrum Scale V4.1.1.0 thru 4.1.1.5 apply V4.1.1.6 at http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%2Bdefined%2Bstorage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.1.1&platform=All&function=all
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
23 May 2016: Original version published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
01 August 2018
UID
ssg1S1005833