IBM Support

Security Bulletin: Samba vulnerability issue on IBM Storwize V7000 Unified (CVE-2013-4408 and CVE-2012-6105)

Security Bulletin


An attacker could gain privileged access to IBM Storwize V7000 Unified system by exploiting a vulnerability in Samba.

Vulnerability Details

CVE ID: CVE-2013-4408 and CVE-2012-6105


This issue affects only those IBM Storwize V7000 Unified systems that use Active Directory server for authentication. Configuration with other authentication server types are not affected by this issue.

IBM Storwize V7000 Unified includes a version of Samba that does not check correctly for buffer overflows in winbindd. This enables remote Active Directory servers to execute arbitrary code in the affected Samba and potentially allows privileged access to the IBM Storwize V7000 Unified system which could potentially result in system unavailability or unauthorized disclosures if access is not otherwise restricted.

Samba is used on the IBM Storwize V7000 Unified system to enable file management and authentication services for Microsoft Windows environments.

CVSS Base Score: 7.5
CVSS Temporal Score: See for the current score

CVSS Base Score: 4.0
CVSS Temporal Score: See for the current score

Affected Products and Versions

IBM Storwize V7000 Unified V1.3.0.0 to V1.4.2.1.


The fix for this issue is available beginning with IBM Storwize V7000 Unified V1.4.3.0. Customers running an earlier version of IBM Storwize V7000 Unified should upgrade to V1.4.3.0 or later in order to get these fixes.

Latest Storwize V7000 Unified Software

Workarounds and Mitigations

Work-around(s): None.

Mitigation(s): Active Directory server should be maintained behind a firewall. Access should be restricted to approved users only.

Get Notified about Future Security Bulletins


Complete CVSS v2 Guide
On-line Calculator v2
Complete CVSS v3 Guide
On-line Calculator v3

Related information



Change History

9 April 2014: First draft

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.


According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: IBM Storwize V7000 Unified (2073)

Version: 1.3, 1.4

Operating system(s): Platform Independent

Reference #: S1004536

Modified date: 09 April 2014