Lucene search

K
ibmIBMEE577BAFA1A3CCCF19C0FC6E283A5304693E2A362D15160235EE29191E536DE9
HistoryAug 01, 2018 - 7:34 p.m.

Security Bulletin: Vulnerability in Samba affects IBM Spectrum Scale SMB protocol access method (CVE-2016-2119)

2018-08-0119:34:30
www.ibm.com
15

0.005 Low

EPSS

Percentile

76.5%

Summary

A Samba vulnerability which could allow a remote attacker to conduct spoofing attacks affects IBM Spectrum Scale SMB protocol access method.

Vulnerability Details

CVEID: CVE-2016-2119 DESCRIPTION: Samba could allow a remote attacker to conduct spoofing attacks. A man-in-the-middle attacker could exploit this vulnerability to inject the SMB2_SESSION_FLAG_IS_GUEST or SMB2_SESSION_FLAG_IS_NULL flags to downgrade the client’s configuration-required signing protections for SMB2 or SMB3 client connections and spoof the server.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114797 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

IBM Spectrum Scale V4.1.1 and V4.2 Standard and Advanced Editions

Remediation/Fixes

Install the latest update for your level of IBM Spectrum Scale.

For V4.2.0.0 thru V4.2.1.0, obtain V4.2.1.1 from Fix Central at:

http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%2Bdefined%2Bstorage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.2.0&platform=All&function=all

For V4.1.1,0 thru V4.1.1.8, obtain V4.1.1.9 from Fix Central at:

http://www-933.ibm.com/support/fixcentral/swg/selectFixes?parent=Software%2Bdefined%2Bstorage&product=ibm/StorageSoftware/IBM+Spectrum+Scale&release=4.1.1&platform=All&function=all

Workarounds and Mitigations

None