SONAS includes a version of the LDAP client which stores the username and the password of the LDAP user in clear text in the local file system.
VULNERABILITY DETAILS:
CVE ID:CVE-2012-0706
DESCRIPTION:
SONAS requires LDAP username (called binddn) and password for authentication purposes when accessing the LDAP server to obtain information about users and groups. SONAS includes an LDAP client implementation which stores the LDAP username and the LDAP password in cleartext in the local file system. A local or a remote attacker who gains root access to SONAS can use this information to gain access to the external LDAP server.
Earlier versions of the SONAS documentation advised SONAS administratorβs to configure an LDAP account with root-like access to the LDAP server. The SONAS documentation has been changed to recommend that customers configure the system to only allow LDAP users with at least privileged access for SONAS to look up data on the LDAP server.
CVSS:
CVSS Base Score: 1.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/73309 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:M/Au:S/C:P/I:N/A:N)
AFFECTED PLATFORMS:
REMEDIATION:
Vendor Fix(es): None. Permanent limitation.
Workaround(s): Updated documentation is available with SONAS 1.3.2.3 and above.
Please refer to below section on infocenter to follow the guidelines.
Administering > Managing > Managing authentication and ID mapping > Configuring the system for authentication > Authentication using an external LDAP server > Setting up external LDAP server prerequisites
Mitigation(s): SONAS customers who configure SONAS with LDAP authentication should configure SONAS using an LDAP user id with least privileges as described in the updated documentation. In addition SSL or TLS should be configured to ensure that the LDAP user name is not transferred in clear text over the network. Please see SONAS Information Center for more details.
REFERENCES:
RELATED INFORMATION:
CHANGE HISTORY:
_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _
_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an βindustry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.β IBM PROVIDES THE CVSS SCORES βAS ISβ WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
[{βProductβ:{βcodeβ:βSTAV45β,βlabelβ:βNetwork Attached Storage (NAS)-\u003EScale Out Network Attached Storageβ},βBusiness Unitβ:{βcodeβ:βBU054β,βlabelβ:βSystems w/TPSβ},βComponentβ:β1.3β,βPlatformβ:[{βcodeβ:βPF016β,βlabelβ:βLinuxβ}],βVersionβ:β1.3β,βEditionβ:ββ,βLine of Businessβ:{βcodeβ:ββ,βlabelβ:ββ}}]