Lucene search

K
ibmIBM8E8952329C5887F29C791DD7D4E5E103D511720BF6D527D2FDD026C914951267
HistoryMay 13, 2021 - 2:26 p.m.

Security Bulletin: Samba for IBM i is affected by CVE-2021-20254

2021-05-1314:26:31
www.ibm.com
21

0.004 Low

EPSS

Percentile

74.4%

Summary

Samba is supported on IBM i. IBM i has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2021-20254
**DESCRIPTION:**Samba could allow a remote authenticated attacker to bypass security restrictions, caused by a coding error when converting SIDs to gids. By sending a specially-crafted request, an attacker could exploit this vulnerability to cause incorrect group entries in the Samba file server process token, and allows unauthorized access to files
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/201081 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM i 7.4
IBM i 7.3
IBM i 7.2

Remediation/Fixes

The issue can be resolved by applying a PTF to IBM i.

Releases 7.4, 7.3, and 7.2 of IBM i are supported and will be fixed.

The IBM i PTF numbers are:

Release 7.4 – SI76294
Release 7.3 – SI76293
Release 7.2 – SI76292

<https://www.ibm.com/support/fixcentral/&gt;

_Important note: _IBM recommends that all users running unsupported versions of affected products upgrade to supported and fixed version of affected products.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm ieq7.1.0