A security vulnerability has been identified in OpenStack Nova that is used by IBM Cloud Manager with OpenStack. This vulnerability only affects IBM Cloud Manager with OpenStack version that ships kilo version of OpenStack.
IBM Cloud Manager with OpenStack has addressed these vulnerabilities.
CVEID: CVE-2017-16239**
DESCRIPTION:** OpenStack Nova could allow a remote authenticated attacker to bypass security restrictions. By rebuilding an instance, an attacker could exploit this vulnerability to achieve Filter Scheduler bypass.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/135002 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
Affected Product Name
|
Affected Versions
—|—
IBM Cloud Manager with OpenStack| 4.3
br>
br>
Product
|
VRMF
|
Remediation / First Fix
—|—|—
IBM Cloud Manager with OpenStack| 4.3| Upgrade to 4.3 FP 10:
http://www.ibm.com/support/fixcentral/quickorder?product=ibm%2FOther+software%2FCloud+Manager+with+Openstack&fixids=4.3.0.10-IBM-CMWO-FP10&source=SAR
br>
br>