FYI…
IBM SmartCloud Entry Appliance: Vulnerabilities in Bash…
- http://www.securitytracker.com/id/1030971
CVE Reference: CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187
Oct 6 2014
Impact: Execution of arbitrary code via local system, Execution of arbitrary code via network, User access via local system, User access via network
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
Version(s): R7.3.0, R7.6.0, R7.7.0, R7.8.0, R7.9.0, R8.1.0 …
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279
2 Oct 2014
> http://xforce.iss.net/xforce/xfdb/96687
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020272
5 Oct 2014
> http://xforce.iss.net/xforce/xfdb/96686
___
Security Bulletin: Vulnerabilities in Bash affect IBM Security Access Manager for Mobile and IBM Security Access Manager for Web (CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, CVE-2014-6278)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733
1 Oct 2014: Original Version Published
Summary: Six Bash vulnerabilities were disclosed in September 2014. This bulletin addresses the vulnerabilities that have been referred to as “Bash Bug” or “Shellshock” and two memory corruption vulnerabilities. Bash is used by IBM Security Access Manager for Mobile and IBM Security Access Manager for Web.
Vulnerability Details: CVE-ID: CVE-2014-6271
DESCRIPTION: GNU Bash could allow a remote attacker to execute arbitrary commands on the system, caused by an error when evaluating specially-crafted environment variables passed to it by the bash functionality. An attacker could exploit this vulnerability to write to files and execute arbitrary commands on the system…
> http://xforce.iss.net/xforce/xfdb/96153 - High Risk
Affected Products and Versions:
- IBM Security Access Manager for Mobile 8.0, firmware versions 8.0.0.0, 8.0.0.1, 8.0.0.3, [removed], and [removed]
- IBM Security Access Manager for Web 7.0 and 8.0, firmware versions 7.0, 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.0.4, 7.0.0.5, 7.0.0.6, 7.0.0.7, 7.0.0.8, 7.0.0.9, 8.0.0.2, 8.0.0.3, 8.0.0.4, and 8.0.0.5
Remediation/Fixes:
IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch…
Security Bulletin: Network Protection is affected by multiple OpenSSL vulnerabilities (CVE-2014-3505, CVE-2014-3506, CVE-2014-3507, CVE-2014-3510, CVE-2014-3511)
- http://www-01.ibm.com/support/docview.wss?uid=swg21684903
Security Bulletin: IBM Security Network Protection is affected by multiple vulnerabilities (CVE-2013-1740, CVE-2014-1490, CVE-2014-1491, CVE-2014-1492, CVE-2014-1544, CVE-2014-1545)
- http://www-01.ibm.com/support/docview.wss?uid=swg21684838
![]()