Flashes (Alerts)
Abstract
SONAS includes multiple software components for which the vendors have provided fixes for security vulnerabilities in such components.
Content
VULNERABILITY DETAILS:
CVE ID:
DESCRIPTION:
SONAS has integrated updated versions of the software components for which the vendors have provided fixes for security vulnerabilities.
CVSS:
Please see vendor documentation for CVSS scores and CVSS vector.
AFFECTED PLATFORMS:
- Affected releases: SONAS 1.1 through 1.3.2.2.
- Releases/systems/configurations NOT affected: SONAS 1.3.2.3 and above.
REMEDIATION:
Vendor Fix(es): The issue was fixed beginning with version SONAS 1.3.2.3. SONAS customers running an earlier SONAS version (e.g. SONAS 1.3.2.1) must upgrade to SONAS 1.3.2.3 or a later version.
Workaround(s): None.
Mitigation(s): SONAS is not exposed to CVEs related to Firefox and Xulrunner and to CVE-2011-3026 during normal operation. Service procedures which use the Firefox web browser may activate the vulnerable code. Service personnel must not browse web pages on the internet to avoid the processing of web pages with malicious content.
The Tomcat related vulnerabilities are exposed to the SONAS management and service IP addresses only, but not to the public IP addresses which are used for NAS data access. It is recommended that the management and service IP addresses will be attached to a management network only.
CVE-2012-4859 is not directly exploitable on SONAS, because SONAS does not provide a capability to logon as native Unix or Linux user.
CVE-2012-5954 impacts only SONAS systems, which are configured with TSM HSM.
REFERENCES:
- Complete CVSS Guide
- On-line Calculator V2
- TSM 6.3.1.0
- RHSA-2012-0128
CVE-2012-4859
CVE-2012-5954
CVE-2011-3639
CVE-2011-4317
CVE-2012-0053
- Apache Tomcat 6.0.33
- Apache Tomcat 6.0.35
- IBM Java 6.0.0 SR12
- RHSA-2012-0143
- RHSA-2012-0317
- RHSA-2012-1210
- RHSA-2012-1350
- RHSA-2012-1361
- RHSA-2012-1407
- RHSA-2012-1482
CVE-2011-1184
CVE-2011-2204
CVE-2011-2526
CVE-2011-3190
CVE-2011-3375
CVE-2012-0022
CVE-2012-5081
CVE-2011-3026
CVE-2011-3026
CVE-2012-1970
CVE-2012-1972
CVE-2012-1973
CVE-2012-1974
CVE-2012-1975
CVE-2012-1976
CVE-2012-3956
CVE-2012-3957
CVE-2012-3958
CVE-2012-3959
CVE-2012-3960
CVE-2012-3961
CVE-2012-3962
CVE-2012-3963
CVE-2012-3964
CVE-2012-3966
CVE-2012-3967
CVE-2012-3968
CVE-2012-3969
CVE-2012-3970
CVE-2012-3972
CVE-2012-3976
CVE-2012-3978
CVE-2012-3980
CVE-2012-1956
CVE-2012-3982
CVE-2012-3986
CVE-2012-3988
CVE-2012-3990
CVE-2012-3991
CVE-2012-3992
CVE-2012-3993
CVE-2012-3994
CVE-2012-3995
CVE-2012-4179
CVE-2012-4180
CVE-2012-4181
CVE-2012-4182
CVE-2012-4183
CVE-2012-4184
CVE-2012-4185
CVE-2012-4186
CVE-2012-4187
CVE-2012-4188
CVE-2012-4193
CVE-2012-4194
CVE-2012-4195
CVE-2012-4196
CVE-2012-4201
CVE-2012-4202
CVE-2012-4207
CVE-2012-4209
CVE-2012-4210
CVE-2012-4214
CVE-2012-4215
CVE-2012-4216
CVE-2012-5829
CVE-2012-5830
CVE-2012-5833
CVE-2012-5835
CVE-2012-5839
CVE-2012-5840
CVE-2012-5841
CVE-2012-5842
RELATED INFORMATION:
CHANGE HISTORY:
- 28/03/2013: Original copy published.
- 03/04/2013: Restructured the document as per new guidelines.
- 30/01/2014: Restructured the document
The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.
Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
Was this topic helpful?
Document Information
Modified date:
25 September 2022
UID
ssg1S1004300