IBM Support

Security Bulletin: A vulnerable issue affects IBM Spectrum LSF Suite, IBM Spectrum LSF and IBM Spectrum LSF Suite Community Edition

Security Bulletin


Summary

There is a vulnerable issue in LSF that an attacker can exploit an authentication weakness in some messages transferred between some binaries through network, to run commands with unauthorized permission. LSF have addressed this security issue (CVE-2020-4983).

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s)Version(s)
IBM Spectrum LSF Suite10.2
IBM Spectrum LSF10.1
IBM Spectrum LSF Suite Community Edition10.2


Remediation/Fixes

a) With LSF 10 FP2 or above, by following the fix in https://www.ibm.com/support/pages/node/630961 to set LSF_EAUTH_KEY in an existing cluster, this security issue can be resolved.

b) For a new installation/upgrade, please see following table.

Product

VRMF

APAR

Remediation/First Fix

Spectrum LSF Suite

10.2

None

Download IBM Spectrum LSF Suite 10.2 Fix Pack 12 from https://www.ibm.com/support/fixcentral, and apply the Fix Pack.

Spectrum LSF

10.1

None

Download IBM Spectrum LSF 10.1 Fix Pack 12, lsf-10.1.0.12-spk-2021-Jun-build600488, from  https://www.ibm.com/support/fixcentral, and apply the Fix Pack.

Spectrum LSF Suite Community Edition

10.2

None

Download IBM Spectrum LSF CE 10.2.0.12 and deploy the cluster.

https://epwt-www.mybluemix.net/software/support/trial/cst/programwebsite.wss?siteId=680&h=null&p=null

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

CVEID:  CVE-2020-4983
DESCRIPTION: IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/192586 for the current score.
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Acknowledgement

This vulnerability was reported to IBM by HPCsec

Change History

22 Dec 2020: Initial Publication
31 Jan 2020: Added LSF CE edition
11 May 2021: Update with the steps to apply this LSF parameter fix for each version
19 Aug 2021: Update with two solutions - one for existing cluster, the other for upgrade with Fix Pack 12

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSZU9Q","label":"IBM Spectrum LSF Suite for Workgroups"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.2","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}},{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSWRJV","label":"IBM Spectrum LSF"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"10.1","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
18 August 2021

UID

ibm16395478