SB2022070422 - Multiple vulnerabilities in IBM Spectrum Protect Plus
Published: July 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2021-20254)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when mapping Windows group identities (SIDs) into unix group identities (gids), which resulted into negative idmap cache entries created in the Samba server process token. An attacker who can manage to trigger the vulnerability can crash the Samba server or potentially perform unauthorized actions on the system.
2) Out-of-bounds read (CVE-ID: CVE-2021-3712)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing ASN.1 strings related to a confusion with NULL termination of strings in array. A remote attacker can pass specially crafted data to the application to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
3) Resource exhaustion (CVE-ID: CVE-2021-43859)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
4) Infinite loop (CVE-ID: CVE-2022-0778)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the BN_mod_sqrt() function when processing an ASN.1 certificate that contains elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. A remote attacker can supply a specially crafted certificate to the TLS server or client, consume all available system resources and cause denial of service conditions.
5) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-25717)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the Windows Active Directory (AD) domains have by default a feature to allow users to create computer accounts. A remote authenticated attacker can create such account with elevated privileges on the system.
6) Input validation error (CVE-ID: CVE-2021-23192)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the DCE/RPC fragment injection issue. A remote attacker can replace subsequent fragments in requests with their own data and alter the server behavior.
7) Resource management error (CVE-ID: CVE-2021-3733)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application within the AbstractBasicAuthHandler class in urllib. A remote attacker with control over the server can perform regular expression denial of service attack during authentication.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-samba-openssl-python-and-xstream-affect-ibm-spectrum-protect-plus-cve-2021-20254-cve-2021-3712-cve-2021-43859-cve-2022-0778-cve-2020-25717-cve-2021-2319/"
- https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-samba-openssl-python-and-xstream-affect-ibm-spectrum-protect-plus-cve-2021-20254-cve-2021-3712-cve-2021-43859-cve-2022-0778-cve-2020-25717-cve-2021-2319/</a><br><a
- https://www.ibm.com/support/pages/node/6596981"
- https://www.ibm.com/support/pages/node/6596981</a><br><br><br></p>