Security Bulletin
Summary
There is a vulnerable issue in LSF that an attacker can exploit an authentication weakness in some messages transferred between some binaries through network, to run commands with unauthorized permission. LSF have addressed this security issue (CVE-2020-4983).
Vulnerability Details
Refer to the security bulletin(s) listed in the Remediation/Fixes section
Affected Products and Versions
Affected Product(s) | Version(s) |
IBM Spectrum LSF Suite | 10.2 |
IBM Spectrum LSF | 10.1 |
IBM Spectrum LSF Suite Community Edition | 10.2 |
Remediation/Fixes
a) With LSF 10 FP2 or above, by following the fix in https://www.ibm.com/support/pages/node/630961 to set LSF_EAUTH_KEY in an existing cluster, this security issue can be resolved.
b) For a new installation/upgrade, please see following table.
Product |
VRMF |
APAR |
Remediation/First Fix |
Spectrum LSF Suite |
10.2 |
None |
Download IBM Spectrum LSF Suite 10.2 Fix Pack 12 from https://www.ibm.com/support/fixcentral, and apply the Fix Pack. |
Spectrum LSF |
10.1 |
None |
Download IBM Spectrum LSF 10.1 Fix Pack 12, lsf-10.1.0.12-spk-2021-Jun-build600488, from https://www.ibm.com/support/fixcentral, and apply the Fix Pack. |
Spectrum LSF Suite Community Edition |
10.2 |
None |
Download IBM Spectrum LSF CE 10.2.0.12 and deploy the cluster. |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
CVEID: CVE-2020-4983
DESCRIPTION: IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/192586 for the current score.
CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Acknowledgement
This vulnerability was reported to IBM by HPCsec
Change History
22 Dec 2020: Initial Publication
31 Jan 2020: Added LSF CE edition
11 May 2021: Update with the steps to apply this LSF parameter fix for each version
19 Aug 2021: Update with two solutions - one for existing cluster, the other for upgrade with Fix Pack 12
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
18 August 2021
UID
ibm16395478