IBM Scale Out Network Attached Storage (SONAS) Information Leakage Vulnerability
Release date:
Updated on:
Affected Systems:
IBM Scale Out Network Attached Storage (SONAS)
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-0706
IBM Scale Out Network Attached Storage (SONAS) is an advanced architecture, flexible, and cluster expansion solution.
The LDAP client of IBM Scale Out Network Attached Storage (SONAS) stores the LDAP user name and password in plaintext in the local file system, local or remote attackers with root access to SONAS can exploit this vulnerability to obtain sensitive information and access the external LDAP server.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://www-01.ibm.com/support/docview.wss? Uid = ssg1S1004292
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.ibm.com/support/fixcentral/