Boletines de Vulnerabilidades

IBM Security Bulletin: IBM SmartCloud Orchestartor - Trustee token revocation does not work with memcache backend (CVE-2014-2237)


Información sobre el sistema

   
Software afectado IBM

Descripción

When a trustor issues a trust token with impersonation enabled, the token is only added to the trustors token list and not to the trustees token list. This results in the trust token not being invalidated by the trustees token revocation (bulk revocation). This is most noticeable when the trustee user is disabled or the trustee changes a password. Only setups using the memcache backend for tokens in Keystone are affected. CVE(s): CVE-2014-2237 Affected product(s) and affected version(s):

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_smartcloud_orchestartor_trustee_token_revocation_does_not_work_with_memcache_backend_cve_2014_2237?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-2237 ,CVE-2014-0453 ,CVE-2014-0460 ,CVE-2014-0105 and CVE-2014-0905.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-08-06

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT