IBM Support

Security Bulletin: Vulnerabilities in SSLv3 and GNU C library (glibc) affect multiple products shipped with Intelligent Cluster (CVE-2014-3566, CVE-2015-0235)

Created by Brian Bedard on
Published URL:
https://www.ibm.com/support/pages/node/867654
867654

Security Bulletin


Summary

Information about security vulnerabilities affecting multiple products shipped as components of Intelligent Cluster has been published in security bulletins. The SSLv3 vulnerability (CVE-2014-3566) is referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. The GNU C library (glibc) vulnerability CVE-2014-3566 is referred to as GHOST.

Vulnerability Details

Summary

Information about security vulnerabilities affecting multiple products shipped as components of Intelligent Cluster has been published in security bulletins. The SSLv3 vulnerability (CVE-2014-3566) is referred to as the Padding Oracle On Downgraded Legacy Encryption (POODLE) attack. The GNU C library (glibc) vulnerability CVE-2014-3566 is referred to as GHOST.

Vulnerability Details

CVE-ID: CVE-2014-3566

Description: Multiple products could allow a remote attacker to obtain sensitive information, caused by a design error when using the SSLv3 protocol. A remote user with the ability to conduct a man-in-the-middle attack could exploit this vulnerability via the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack to decrypt SSL sessions and calculate the plaintext of secure connections.

CVSS Base Score: 4.3
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/97013 for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVE-ID: CVE-2015-0235

Description: The gethostbyname functions of the GNU C Library (glibc) are vulnerable to a buffer overflow. By sending a specially crafted, but valid hostname argument, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the targeted process or cause the process to crash. The impact of an attack depends on the implementation details of the targeted application or operating system. This issue is being referred to as the "Ghost" vulnerability.

CVSS Base Score: 7.6
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/100386 for current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C)

Please consult the security bulletins below for vulnerability details and information about fixes.

Note: Not all supported products have a corresponding security bulletin.

Affected products and versions

Affected Supporting Product Fix Version Intelligent Cluster Best Recipe
IBM BladeCenter AMM 3.66N 15B (07/2015)
IBM System x Integrated Management Module 4.97 (1AOO66M) 15B (07/2015)
IBM Flex System Integrated Management Module 4.90 (1AOO66O) 15B (07/2015)
IBM Flex System Chassis Management Module (CMM) 2.5.3T (2PET12T) 15B (07/2015)
IBM RackSwitch G8264 7.9.12.0 15B (07/2015)
IBM RackSwitch G8264T 7.9.12.0 15B (07/2015)
IBM Flex System FC3171 9.1.5.02.00 15B (07/2015)
IBM Flex System FC5022 16Gb SAN Switch 7.3.1 15B (07/2015)
IBM Flex System EN6131 40 Gb Ethernet / IB6131 40Gb Infiniband Switch 9.1.5.02.00 15B (07/2015)
IBM GCM16-GCM32 KVM 1.26.1.23978 15B (07/2015)
IBM SAN24B Series Switches 6.2.2g
7.2.1d
15B (07/2015)
Brocade 8Gb SAN Switch Module for IBM BladeCenter 7.2.1d 15B (07/2015)
Brocade 10Gb SAN Switch Module for IBM BladeCenter 6.4.3_dcb3 15B (07/2015)
Brocade 4Gb SAN Switch Module for IBM BladeCenter 7.2.1d
7.3.0c
15B (07/2015)
IBM Converged Switch B32 6.4.3_dcb3 15B (07/2015)
Intel Xeon Phi PCIe adapters 3.4.3 15B (07/2015)
DDN SFA12000 and SFA7700 2.3.0.3-23217 15B (07/2015)
Cisco Nexus 5596UP 5.2(1)N1(9) 15B (07/2015)
Storwize V3700 7.4.0.4 15B (07/2015)
Intel True Scale Fabric Switches 12000 Series 7.3.1.0.10 15B (07/2015)
Juniper EX Series Switches 12.3R9 15B (07/2015)
Mellanox SX65XX, SX6036, SX1036 and SX6036G 3.4.2008 15B (07/2015)

Related Information
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
Intelligent Cluster Security Bulletin Readme

Change History
06 August 2015: Original Copy Published

Get Notified about Future Security Bulletins

References

On

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

Operating System

BladeCenter:Operating system independent / None

System x Hardware Options:Operating system independent / None

PureFlex System and Flex System:Operating system independent / None

Lenovo Intelligent Cluster Solutions:Operating system independent / None

[{"Type":"HW","Business Unit":{"code":"BU016","label":"Multiple Vendor Support"},"Product":{"code":"HW20M","label":"BladeCenter->BladeCenter T Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"","label":""}},{"Type":"HW","Business Unit":{"code":"BU016","label":"Multiple Vendor Support"},"Product":{"code":"HW20T","label":"BladeCenter->BladeCenter E Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"","label":""}},{"Type":"HW","Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"HW21Y","label":"BladeCenter H Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB57","label":"Power"}},{"Type":"HW","Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"HW22P","label":"BladeCenter S Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB57","label":"Power"}},{"Type":"HW","Business Unit":{"code":"BU016","label":"Multiple Vendor Support"},"Product":{"code":"HW22Q","label":"BladeCenter->BladeCenter HT Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB57","label":"Power"}},{"Type":"HW","Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"HW22P","label":"BladeCenter S Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB57","label":"Power"}},{"Type":"HW","Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"HW94A","label":"Flex System Manager Node"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"LOB57","label":"Power"}},{"Type":"HW","Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"HW94F","label":"Enterprise Chassis"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"","label":""}},{"Type":"HW","Business Unit":{"code":"BU016","label":"Multiple Vendor Support"},"Product":{"code":"HWNA0","label":"Lenovo Intelligent Cluster Solutions"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
14 April 2023

UID

ibm1MIGR-5098516