There is a vulnerability in the Linux Pluggable Authentication Module (PAM) to which the IBM® FlashSystem™ V840 is susceptible. An exploit of this vulnerability could allow a remote attacker to expose sensitive information and/or cause a denial of service.
CVEID: CVE-2015-3238 DESCRIPTION: Linux-PAM could allow a local attacker to obtain sensitive information, caused by an error in the _unix_run_helper_binary function in the pam_unix module. An attacker could exploit this vulnerability using an overly large password to enumerate usernames and cause the system to hang.
CVSS Base Score: 5.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/106368 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
FlashSystem V840 including machine type and models (MTMs) for all available code levels. MTMs affected include 9846-AE1, 9848-AE1, 9846-AC0, 9848-AC0, 9846-AC1, and 9848-AC1.
V840 MTMs
| VRMF| APAR| Remediation/First Fix
—|—|—|—
Storage nodes:
9846-AE1 &
9848-AE1
Control nodes: 9846-AC0,
9846-AC1,
9848-AC0 &
9848-AC1| _Code fixes are now available, the minimum VRMF containing the fix depends on the code stream:
Storage Node VRMF . _
1.4 stream: 1.4.0.10 (or later)
1.3 stream: 1.3.0.5 (or later)
1.2 stream: 1.2.1.9 (or later)
Controller Node VRMF .
7.6 stream: 7.6.0.4 (or later)
7.5 stream: 7.5.0.7 (or later)
7.4 stream: 7.4.0.9 (or later)| _ _N/A| No workarounds or mitigations, other than applying this code fix, are known for this vulnerability
FlashSystem V840 fixes**for storage and controller node **are available @ IBM’s Fix Central
None