IBM Support

Security Bulletin: Vulnerabilities in OpenSSL affect the IBM Tivoli Storage Manager Client and IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (CVE-2014-3569, CVE-2014-3570, CVE-2014-3572, CVE-2014-8275, CVE-2015-0204)

Security Bulletin


Summary

OpenSSL vulnerabilities were disclosed on January 8, 2015 by the OpenSSL Project. This includes "FREAK: Factoring Attack on RSA-EXPORT keys" TLS/SSL client and server vulnerabilities. OpenSSL, used by the Tivoli Storage Manager Client, has addressed the applicable CVEs.

Vulnerability Details

CVEID: CVE-2014-3569
DESCRIPTION:
OpenSSL is vulnerable to a denial of service, caused by the failure to properly handle attempts to use unsupported protocols by the ssl23_get_client_hello function in s23_srvr.c. A remote attacker could exploit this vulnerability using an unexpected handshake to trigger a NULL pointer dereference and cause the daemon to crash.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99706 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVEID: CVE-2014-3570
DESCRIPTION:
An unspecified error in OpenSSL related to the production of incorrect results on some platforms by Bignum squaring (BN_sqr) has an unknown attack vector and impact.
CVSS Base Score: 2.6
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99710 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N)

CVEID: CVE-2014-3572
DESCRIPTION:
OpenSSL could provide weaker than expected security. The client accepts a handshake using an ephemeral ECDH ciphersuite with the server key exchange message omitted. An attacker could exploit this vulnerability to launch further attacks on the system.
CVSS Base Score: 1.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99705 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:H/Au:N/C:N/I:P/A:N)

CVEID: CVE-2014-8275
DESCRIPTION:
OpenSSL could allow a local attacker to bypass security restrictions, caused by the modification of the fingerprint without breaking the signature. An attacker could exploit this vulnerability using non-DER or invalid encodings outside the signed portion of a certificate bypass security restrictions and perform unauthorized actions.
CVSS Base Score: 1.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99709 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:H/Au:N/C:N/I:P/A:N)

CVEID: CVE-2015-0204
DESCRIPTION:
A vulnerability in the OpenSSL ssl3_get_key_exchange function could allow a remote attacker to downgrade the security of certain TLS connections. An OpenSSL client accepts the use of an RSA temporary key in a non-export RSA key exchange ciphersuite. This could allow a remote attacker using man-in-the-middle techniques to facilitate brute-force decryption of TLS/SSL traffic between vulnerable clients and servers. This vulnerability is also known as the FREAK attack.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/99707 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N)

Affected Products and Versions

This security exposure affects network connections between the Tivoli Storage Manager (IBM Spectrum Protect) Client and VMware or NetApp services only. This exposure affects:

  • Tivoli Storage Manager Client levels:
    - 7.1.0.0 through 7.1.2.x - NetApp services with AIX, Linux x86, Windows 32, and Windows x64 clients
    - 7.1.0.0 through 7.1.3.1 - VMware services with Linux x86 and Windows x64 clients
    - 6.4.0.0 through 6.4.2.x - NetApp services with AIX and Linux x86 clients
    - 6.4.0.0 through 6.4.3.1 - NetApp services with Windows x32 and Windows x64 clients
    - 6.4.0.0 through 6.4.3.1 - VMware services with Linux x86, Windows x32, and Windows x64 clients
    - 6.3 all levels - NetApp and VMware services
    - 6.2 all levels (NetApp only) - TSM 6.2 is beyond End of Support
    - 6.1 all levels (NetApp only) - TSM 6.1 is beyond End of Support
  • Tivoli Storage Manager for Virtual Environments: Data Protection for VMware levels:
    - 7.1.0.0 through 7.1.3.x - TSM Linux x86 and Windows x64 clients are shipped with 7.1 and are used as the data mover
    - 6.4 all levels when used with an affected TSM client data mover level
    - 6.3 all levels when used with an affected TSM client data mover level

Remediation/Fixes

Tivoli Storage Manager Client Release Fixing VRM Level

Platform
Link to Fix / Fix Availability Target
7.1 7.1.4 NetApp and VMware
Linux x86
Windows x64
NetApp Only
Windows x32
AIX
http://www.ibm.com/support/docview.wss?uid=swg24041076
6.4 6.4.3.2 NetApp and VMware
Linux x86
Windows x64
NetApp Only
Windows x32
http://www.ibm.com/support/docview.wss?uid=swg24041144
6.4 6.4.3.0 NetApp Only
AIX
http://www.ibm.com/support/docview.wss?uid=swg24040185
6.4 VMware
Windows x32
IBM recommends upgrading the machine to 64-bit and using the TSM 6.4 or 7.1 Windows x64 client with the 7.1.4 or 6.4.3.2 fix. Please refer to APAR IT13174 for more information about Windows x32 and VMware backups.
6.3 IBM recommends VMware and NetApp users upgrade to a fixed level (7.1.4, 6.4.3.2 for all platforms except AIX or 6.4.3.0 for NetApp AIX).
6.2 and 6.1 IBM recommends NetApp users upgrade to a fixed level (7.1.4, 6.4.3.2 for all platforms except AIX or 6.4.3.0 for AIX).

Tivoli Storage Manager for Virtual Environments: Data Protection for VMware Release Fixing VRM Level
Platform
Link to Fix / Fix Availability Target
7.1 7.1.4 Linux x86
Windows x64
http://www.ibm.com/support/docview.wss?uid=swg24041094
6.4 Linux x86
Windows x64
Apply the TSM client fixing level (6.4.3.2)
6.4 Windows x32 IBM recommends upgrading the machine to 64-bit and using the TSM 6.4 Windows x64 client with the 6.4.3.2 fix. Please refer to APAR IT13174 for more information about Windows x32 and Data Protection for VMware
6.3 IBM recommends Tivioli Storage Manager for Virtual Environments: Data Protection for VMware 6.3 users upgrade to 6.4 and apply the TSM client fixing level (6.4.3.2) or upgrade to 7.1.4.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Complete CVSS v2 Guide
On-line Calculator v2

Related information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Acknowledgement

None

Change History

21 December 2015 - Original version published
01 February 2016 - 1) Updated Summary; 2) Updated Affected products to remove only TSM for VE: DP for VMware is affected by VMware as the client is also affected due to VMware backups; 3) In Remediation/Fixes, the link to TSM 7.1.4 was incorrect; 4) In Remediation/Fixes, added row for TSM client 6.4 Windows x32 platform; 5) n Remediation/Fixes, added row for TSM for VE: DP for VMware 6.4 Windows x32 platform.

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Cross reference information
Segment Product Component Platform Version Edition
Storage Management Tivoli Storage Manager for Virtual Environments Data Protection for VMware Linux, Windows 6.3, 6.4, 7.1
Storage Management Tivoli Storage Manager Extended Edition Client AIX, Linux, Windows 6.1, 6.2, 6.3, 6.4, 7.1 All Editions

Document information

More support for: Tivoli Storage Manager
Client

Software version: 6.1, 6.2, 6.3, 6.4, 7.1

Operating system(s): AIX, Linux, Windows

Software edition: All Editions

Reference #: 1973383

Modified date: 23 August 2017


Translate this page: