IBM Support

Security Bulletin: SONAS Update Includes Fixes for Multiple Vendor Security Vulnerabilities

Flashes (Alerts)


Abstract

SONAS includes multiple software components for which the vendors have provided fixes for security vulnerabilities in such components.

Content

VULNERABILITY DETAILS:

CVE ID:

VendorVendor IDVendor TitleIncluded CVEs
IBMTSM 6.3.1.0Two unauthorized access vulnerabilities in IBM TSM for Space ManagementCVE-2012-4859
CVE-2012-5954
Red HatRHSA-2012-0128Moderate: httpd security updateCVE-2011-3639
ApacheApache Tomcat 6.0.33Fixed in Apache Tomcat 6.0.33CVE-2011-1184
ApacheApache Tomcat 6.0.35Fixed in Apache Tomcat 6.0.35CVE-2011-3190
IBMIBM Java 6.0.0 SR12Oracle October 16 2012 CPUCVE-2012-5081
Red HatRHSA-2012-0143Critical: xulrunner security updateCVE-2011-3026
Red HatRHSA-2012-0317Important: libpng security updateCVE-2011-3026
Red HatRHSA-2012-1210Critical: firefox security updateCVE-2012-1970
CVE-2012-1972
CVE-2012-1973
CVE-2012-1974
CVE-2012-1975
CVE-2012-1976
CVE-2012-3956
CVE-2012-3957
CVE-2012-3958
CVE-2012-3959
CVE-2012-3960
CVE-2012-3961
CVE-2012-3962
CVE-2012-3963
CVE-2012-3964
CVE-2012-3966
CVE-2012-3967
CVE-2012-3968
CVE-2012-3969
CVE-2012-3970
CVE-2012-3972
CVE-2012-3976
CVE-2012-3978
CVE-2012-3980
Red HatRHSA-2012-1350Critical: firefox security and bug fix updateCVE-2012-1956
CVE-2012-3982
CVE-2012-3986
CVE-2012-3988
CVE-2012-3990
CVE-2012-3991
CVE-2012-3992
CVE-2012-3993
CVE-2012-3994
CVE-2012-3995
CVE-2012-4179
CVE-2012-4180
CVE-2012-4181
CVE-2012-4182
CVE-2012-4183
CVE-2012-4184
CVE-2012-4185
CVE-2012-4186
CVE-2012-4187
CVE-2012-4188
Red HatRHSA-2012-1361Critical: xulrunner security updateCVE-2012-4193
Red HatRHSA-2012-1407Critical: firefox security updateCVE-2012-4194
CVE-2012-4195
CVE-2012-4196
Red HatRHSA-2012-1482Critical: firefox security updateCVE-2012-4201
CVE-2012-4202
CVE-2012-4207
CVE-2012-4209
CVE-2012-4210
CVE-2012-4214
CVE-2012-4215
CVE-2012-4216
CVE-2012-5829
CVE-2012-5830
CVE-2012-5833
CVE-2012-5835
CVE-2012-5839
CVE-2012-5840
CVE-2012-5841
CVE-2012-5842
Red HatRHSA-2012-0699Moderate: openssl security and bug fix update CVE-2012-2333
Red HatRHSA-2012-0518Important: openssl security update CVE-2012-2110
Red HatRHSA-2012-0426Moderate: openssl security and bug fix update CVE-2012-0884
CVE-2012-1165

DESCRIPTION:
SONAS has integrated updated versions of the software components for which the vendors have provided fixes for security vulnerabilities.


CVSS:
Please see vendor documentation for CVSS scores and CVSS vector.


AFFECTED PLATFORMS:
  • Affected releases: SONAS 1.1 through 1.3.2.2.
  • Releases/systems/configurations NOT affected: SONAS 1.3.2.3 and above.

REMEDIATION:


Vendor Fix(es): The issue was fixed beginning with version SONAS 1.3.2.3. SONAS customers running an earlier SONAS version (e.g. SONAS 1.3.2.1) must upgrade to SONAS 1.3.2.3 or a later version.


Workaround(s): None.

Mitigation(s): SONAS is not exposed to CVEs related to Firefox and Xulrunner and to CVE-2011-3026 during normal operation. Service procedures which use the Firefox web browser may activate the vulnerable code. Service personnel must not browse web pages on the internet to avoid the processing of web pages with malicious content.

The Tomcat related vulnerabilities are exposed to the SONAS management and service IP addresses only, but not to the public IP addresses which are used for NAS data access. It is recommended that the management and service IP addresses will be attached to a management network only.

CVE-2012-4859 is not directly exploitable on SONAS, because SONAS does not provide a capability to logon as native Unix or Linux user.

CVE-2012-5954 impacts only SONAS systems, which are configured with TSM HSM.




REFERENCES:
RELATED INFORMATION:



CHANGE HISTORY:
  • 28/03/2013: Original copy published.
  • 03/04/2013: Restructured the document as per new guidelines.
  • 30/01/2014: Restructured the document

The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash.


Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

[{"Product":{"code":"STAV45","label":"Network Attached Storage (NAS)-\u003EScale Out Network Attached Storage"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"1.3.2","Platform":[{"code":"PF016","label":"Linux"}],"Version":"1.3.2","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
25 September 2022

UID

ssg1S1004300