Lucene search

K
ibmIBMB45C4787E38D863DFD87F5A356D1CBE635AB5ECF2623E99E1FAEEF4CD5CFBFF4
HistoryDec 20, 2019 - 8:47 a.m.

Security Bulletin: SMB signing not required in IBM Spectrum Protect Plus (CVE-2016-2115)

2019-12-2008:47:33
www.ibm.com
74

0.003 Low

EPSS

Percentile

65.9%

Summary

IBM Spectrum Protect Plus is vulnerable to man-in-the-middle attacks as it does not make SMB signing mandatory.

Vulnerability Details

CVEID:CVE-2016-2115
**DESCRIPTION:**Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
CVSS Base score: 4.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/111942 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Plus 10.1.0-10.1.4

Remediation/Fixes

Spectrum Protect Plus Release First Fixing VRM Level ** APAR** Platform Link to Fix
10.1 10.1.5 IT30175 Linux <http://www.ibm.com/support/docview.wss?uid=ibm11072392&gt;

Workarounds and Mitigations

None