Lucene search

K
ibmIBMD4E5C893A250FEAE3B156BCBD1DEEF2119A50FFC25619BC8C5AF90EB197582DB
HistoryAug 14, 2021 - 3:30 a.m.

Security Bulletin: IBM Transparent Cloud Tiering is affected by a vulnerability in Apache Commons IO ( CVE-2021-29425)

2021-08-1403:30:51
www.ibm.com
12
ibm
transparent cloud tiering
apache commons io
vulnerability
cve-2021-29425
ibm spectrum scale
gpfs
version 1.1.1-1.1.8.4
remote attacker
improper input validation
file traversal

EPSS

0.002

Percentile

57.2%

Summary

apache commons IO is used by IBM Spectrum Scale Transparent Cloud Tiering. IBM Spectrum Scale Transparent Cloud Tiering has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2021-29425
**DESCRIPTION:**Apache Commons IO could allow a remote attacker to traverse directories on the system, caused by improper input validation by the FileNameUtils.normalize method. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/โ€ฆ/) to view arbitrary files on the system.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/199852 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
gpfs.tct.client 1.1.5
gpfs.tct.server 1.1.2
gpfs.tct.server 1.1.6
gpfs.tct.client 1.1.3
gpfs.tct.client 1.1.2
gpfs.tct.server 1.1.1
gpfs.tct.client 1.1.1
gpfs.tct.server 1.1.5
gpfs.tct.server 1.1.4
gpfs.tct.server 1.1.7
gpfs.tct.server 1.1.3
gpfs.tct.server 1.1.8

Remediation/Fixes

For Transparent Cloud Tiering 1.1.1.0 thru 1.1.8.4, apply Transparent Cloud Tiering 1.1.8.4 bundled with IBM Spectrum Scale V5.1.1.3 available from FixCentral at:

https://www-945.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%20defined%20storage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=5.1.1&platform=All&function=all

Workarounds and Mitigations

None