Lucene search

K
ibmIBM662DD66D84A5337666DFEFCB42253D8FEF0B1E3EE5CB87968BEB6411F8E57237
HistoryJan 31, 2019 - 2:10 a.m.

Security Bulletin: Vulnerability with event processing affects IBM Flex System Manager (FSM)

2019-01-3102:10:01
www.ibm.com
6

EPSS

0

Percentile

5.1%

Summary

Event processing can allow an attacker to execute commands with elevated privileges. (CVE-2015-1992)

Vulnerability Details

Summary

Event processing can allow an attacker to execute commands with elevated privileges. (CVE-2015-1992)

Vulnerability Details

CVE-ID: CVE-2015-1992

Description: An unspecified vulnerability in event processing could allow an attacker to execute commands with elevated privileges.

CVSS Base Score: 6.9
CVSS Temporal Score: See <http://exchange.xforce.ibmcloud.com/vulnerabilities/103846&gt; for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C)

Affected Products and Versions

  • Flex System Manager 1.1.x.x
  • Flex System Manager 1.2.0.x
  • Flex System Manager 1.2.1.x
  • Flex System Manager 1.3.0.x
  • Flex System Manager 1.3.1.x
  • Flex System Manager 1.3.2.x
  • Flex System Manager 1.3.3.x

Remediation/Fixes

Product VRMF APAR Remediation
Flex System Manager 1.3.3.x IT10337 Install fsmfix1.3.3.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing.
Flex System Manager 1.3.2.x IT10337 Install fsmfix1.3.2.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing.
Flex System Manager 1.3.1.x IT10337 Install fsmfix1.3.1.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing.

Warning: This release contains other vulnerabilities for which IBM has not published a fix. IBM recommends upgrading to FSM 1.3.3.0 and following the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.3.0.x | IT10337 | Install fsmfix1.3.0.0_IT10337 then use smcli cfgEAPFilter to secure event processing.

Warning: This release contains other vulnerabilities for which IBM has not published a fix. IBM recommends upgrading to FSM 1.3.3.0 and following the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.2.1.x | IT10337 | IBM is no longer providing code updates for this release, upgrade to FSM 1.3.3.0 and follow the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.2.0.x | IT10337 | IBM is no longer providing code updates for this release, upgrade to FSM 1.3.3.0 and follow the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.1.x.x | IT10337 | Effective April 30, 2015, IBM has discontinued service for these version/release/modification/fix levels.

Workarounds and Mitigation

None.

Reference

Related Information
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Acknowledgement

None.

Change History
24 September 2015: Original version published

  • The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an “industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.” IBM PROVIDES THE CVSS SCORES “AS IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

EPSS

0

Percentile

5.1%

Related for 662DD66D84A5337666DFEFCB42253D8FEF0B1E3EE5CB87968BEB6411F8E57237