Lucene search

K
ibmIBM924FD2E8A5032ED7C22DF8341BBF235C72A5E6A9B17ED71F350A5B494B8D805A
HistoryMay 02, 2019 - 10:15 a.m.

Security Bulletin: Samba vulnerability affects IBM Storwize V7000 Unified (CVE-2019-3880)

2019-05-0210:15:01
www.ibm.com
14

0.002 Low

EPSS

Percentile

61.2%

Summary

IBM Storwize V7000 Unified is shipped with Samba, for which a fix is available for security vulnerability.

Vulnerability Details

CVEID: CVE-2019-3880 DESCRIPTION: Samba could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted “winreg_SaveKey” request to create a new registry hive file outside a Samba share.
CVSS Base Score: 6.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159188&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

IBM Storwize V7000 Unified
The product is affected when running code releases 1.6.0.0 to 1.6.2.5

Remediation/Fixes

A fix for this issue is in version 1.6.2.6 of IBM Storwize V7000 Unified. Customers running an affected version of IBM Storwize V7000 Unified should upgrade to 1.6.2.6 or a later version.

Latest Storwize V7000 Unified Software

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm storwize v7000 unified (2073)eq1.6