Friday, May 6, 2016

IBM Security Bulletin: The GPFS pattern provided with IBM PureApplication System is affected by a security vulnerability. (CVE-2015-7403)

A security vulnerability has been identified in the current levels of IBM Spectrum Scale V4.1.1, IBM GPFS V4.1 and V3.5 that could allow a local attacker to cause the node they are on to crash. IBM PureApplication System provides a GPFS pattern and addressed the applicable CVE.



CVE(s): CVE-2015-7403


Affected product(s) and affected version(s):

· IBM PureApplication System V2.0 (GPFS Pattern type 1.2.0.0, 1.2.0.1, and 1.2.0.2) using IBM GPFS V3.5.0.19
· IBM PureApplication System V2.1.0.1 (GPFS Pattern type 1.2.1.0) using IBM GPFS V4.1.0.5
· IBM PureApplication System V2.1.0.2 (GPFS Pattern type 1.2.2.0) using IBM GPFS V4.1.0.7
· IBM PureApplication System V2.1.1.0 (GPFS Pattern type 1.2.3.0) using IBM GPFS V4.1.0.7
· IBM PureApplication System V2.1.2.0 (GPFS Pattern type 1.2.4.0) using IBM GPFS V4.1.1.2
· IBM PureApplication System V2.2.0 (GPFS Pattern type 1.2.5.0) using IBM GPFS V4.1.1.3



Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/21E2rqB
X-Force Database: http://ift.tt/1NlIzWK


from IBM Product Security Incident Response Team http://ift.tt/21E2u5I

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.