IBM Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models V840 and V9000
There are vulnerabilities in Java to which the IBM FlashSystem V840 and FlashSystem V9000 are susceptible (CVE-2017-18017 and CVE-2017-17449). An exploit of CVE-2017-18017 could allow a remote attacker to cause a denial of service condition. An exploit of CVE-2017-17449 could allow an attacker to obtain sensitive information.
CVE(s): CVE-2017-18017, CVE-2017-17449
Affected product(s) and affected version(s):
Storage Node machine type and models (MTMs) affected:
- 9846-AE1 and 9848-AE1
- 9846-AE2 and 9848-AE2
- 9846-AE3 and 9848-AE3
Controller Node MTMs affected:
- 9846-AC0 and 9848-AC0
- 9846-AC1 and 9848-AC1
- 9846-AC2 and 9848-AC2
- 9846-AC3 and 9848-AC3
Supported storage node code versions which are affected
- VRMFs prior to 1.4.8.2
- VRMFs prior to 1.5.2.5
- VRMFs prior to 1.6.1.0
Supported controller node code versions which are affected
· VRMFs prior to 7.8.1.8
· VRMFs prior to 8.1.3.3
· VRMFs prior to 8.2.0.0
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10957179
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/137122
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/136106
The post IBM Security Bulletin: Multiple Vulnerabilities in the Linux kernel affect the IBM FlashSystem models V840 and V9000 appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/2MANPto