First published: Tue Mar 24 2015(Updated: )
IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM General Parallel File System | =3.4 | |
IBM General Parallel File System | =3.5 | |
IBM General Parallel File System | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0198 has a high severity rating due to the potential for remote authentication bypass and arbitrary code execution as root.
To fix CVE-2015-0198, upgrade your IBM General Parallel File System to the latest version that addresses this vulnerability.
CVE-2015-0198 affects IBM General Parallel File System versions 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7.
The potential impact of CVE-2015-0198 includes unauthorized remote access and execution of arbitrary programs with root privileges.
CVE-2015-0198 can be exploited by remote attackers using specific cipherList configurations.