Database/Control plane, storage & DevOps

IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobs
Impact
A user who is merely allowed to submit LSF jobs can execute arbitrary commands, via an authentication weakness backed by hard-coded credentials. Job-submission rights are the lowest privilege a cluster hands out, so this promotes every tenant to command execution in the scheduler's context.
Who can reach it
A user on the local network holding ordinary LSF job-submission privileges. Affects Spectrum LSF 10.1 and LSF Suite 10.2.
What to do
Apply IBM's fix for Spectrum LSF. Hard-coded credentials mean the secret is public once the binary is - patching is the only real mitigation, network restriction only narrows who can try.
References
Related entries
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachCVE-2021-26331 · AMD System Management Unit (SMU) mailbox interfaceHigh
- Linux iSCSI: iSCSI netlink structures lack length checksCVE-2021-27365 · Linux iSCSIHigh
- IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage ScaleCVE-2021-29740 · IBM Spectrum Scale core component (format string handling)High
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeCVE-2022-29919 · Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191High
- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureCVE-2022-3650 · CephHigh
- Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlCVE-2022-37459 · Ampere Altra before 1.08g and Altra Max before 2.05a - return address predictionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.