Vulnerability Bulletins

IBM Security Bulletin: IBM SmartCloud Orchestrator - Keystone V2 trusts privilege escalation through user supplied project id (CVE-2014-3520)

   
Affected software IBM
 
By using an out of scope project id, a trustee may gain unauthorized access if the trustor has the required roles in the requested project id. All Keystone deployments configured to enable trusts and V2 API are affected. CVE(s): CVE-2014-3520 Affected product(s) and affected version(s): SmartCloud Orchestrator 2.3, SmartCloud Orchestrator 2.3 FixPack1 up to iFix 4 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_smartcloud_orchestrator_keystone_v2_trusts_privilege_escalation_through_user_supplied_project_id_cve_2014_3520?lang=en_us