Event processing can allow an attacker to execute commands with elevated privileges. (CVE-2015-1992)
Event processing can allow an attacker to execute commands with elevated privileges. (CVE-2015-1992)
CVE-ID: CVE-2015-1992
Description: An unspecified vulnerability in event processing could allow an attacker to execute commands with elevated privileges.
CVSS Base Score: 6.9
CVSS Temporal Score: See <http://exchange.xforce.ibmcloud.com/vulnerabilities/103846> for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Product | VRMF | APAR | Remediation |
---|---|---|---|
Flex System Manager | 1.3.3.x | IT10337 | Install fsmfix1.3.3.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing. |
Flex System Manager | 1.3.2.x | IT10337 | Install fsmfix1.3.2.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing. |
Flex System Manager | 1.3.1.x | IT10337 | Install fsmfix1.3.1.0_IT10337 then use “smcli cfgEAPFilter” to secure event processing. |
Warning: This release contains other vulnerabilities for which IBM has not published a fix. IBM recommends upgrading to FSM 1.3.3.0 and following the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.3.0.x | IT10337 | Install fsmfix1.3.0.0_IT10337 then use smcli cfgEAPFilter to secure event processing.
Warning: This release contains other vulnerabilities for which IBM has not published a fix. IBM recommends upgrading to FSM 1.3.3.0 and following the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.2.1.x | IT10337 | IBM is no longer providing code updates for this release, upgrade to FSM 1.3.3.0 and follow the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.2.0.x | IT10337 | IBM is no longer providing code updates for this release, upgrade to FSM 1.3.3.0 and follow the appropriate remediation for all vulnerabilities.
Flex System Manager | 1.1.x.x | IT10337 | Effective April 30, 2015, IBM has discontinued service for these version/release/modification/fix levels.
None.
Related Information
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
None.
Change History
24 September 2015: Original version published
Disclaimer
According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an “industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.” IBM PROVIDES THE CVSS SCORES “AS IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.