• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Samba Patch Caps Busy Year for IBM i Security

    December 4, 2019 Alex Woodie

    IBM last week patched a moderately severe security flaw in IBM i’s Samba implementation that could enable hackers to access data they really shouldn’t be able to access. The disclosure caps a rather busy second half of the year for security patches on IBM i that saw 26 emergency PTFs and Yum updates for Node.js, Python, the Apache HTTP Server, OpenSSL, ISC Bind, IBM Navigator, and even Db2 Mirror for IBM i.

    On November 26, IBM issued this security bulletin to let people know about the new flaw in the Samba client. The flaw could allow a hacker to not only access files and folders on the affected server that are outside of the SMB network pathnames, but to also create files outside of the working directory, according to IBM’s description. The flaw, which carries a CVSS Base Score of 5.3, was fixed with a series of PTFs for IBM i 7.2, 7.3, and 7.4.

    It was the second patch that month, with the first coming on November 4, when IBM issued a security bulletin that discussed four separate vulnerabilities in Python that impact IBM i versions 7.2 through 7.4. All of the Python vulnerabilities are in the open source programing language, which runs on IBM i via the PASE Unix runtime, and not in any code that’s unique to IBM i.

    The Python flaws include CVE-2019-16935, which describes a problem in the XML-RPC server component of Python version 2 and 3 that could allow untrusted, arbitrary JavaScript to be run. This flaw contains a CVSS Base Score of 6.1.

    A more serious Python problem is CVE-2019-10160, which could allow an attacker to obtain sign-in information, cookies, and other sensitive data by sending a specially crafted URL. The flaw, which impacts Python version 2 and 3 releases, carries a CVSS Base Score of 7.5, making it a severe flaw.

    Another nasty bugger is CVE-2019-9948, which is a Python 2 flaw that could allow an attacker to bypass a protection scheme and allow a blacklisted website to be opened. This little darling carries a CVSS Base Score of 5.3.

    The final Python flaw, CVE-2019-9947, is a new twist on an old Python 2 and 3 bugger (CVE-2019-9740) that could allow an attacker to carry out a Carriage Return Line Feed (CFLF) injection attack using a malformed website. This flaw carries a CVSS Base Score of 6.1.

    All four Python flaws have been fixed on IBM i 7.2 through 7.4. The fix is to upgrade to the latest versions of Python version 2 or 3, either via the Yum command line tool or via the GUI in ACS Package Management.

    Good IT Jungle readers who read Doug Bidwell’s weekly IBM i PTF Guide will have already received word of the patches and (hopefully) applied them, but we are repeating them here just in case.

    Also on the radar this fall is the cross-site scripting vulnerability in IBM Navigator. On October 31, IBM X-Force issued a vulnerability report for the flaw, which can allow an attacker to embed arbitrary JavaScript code in the Web interface, potentially enabling the attacker to gain sign-on credentials to a protected session.

    The CVE-2019-4450 vulnerability was given a CVSS Base Score of 6.1, which is a moderate vulnerability. On the same day, IBM issued three patches for the flaw, one each for IBM i 7.2, 7.3, and 7.4, according to this security bulletin. There are no work arounds and IBM recommended applying the PTF immediately.

    On October 24, IBM issued this security bulletin to let customers know about six security vulnerabilities discovered in the IBM i HTTP Server (the one that’s powered by Apache). The most serious, CVE-2019-9517, describes a DOS attack that could be undertaken by sending a stream of requests of a large response object. It has a CVSS Base Score of 7.5.

    Also concerning is CVE-2019-10081, which is another DOS attack caused by memory corruption that carries a CVSS Base Score of 5.3. With CVE-2019-10082, which also carries a CVSS Base Score of 5.3, remote attackers could obtain sensitive information. A cross-site scripting vulnerability with a CVSS Base Score of 4.7 is at the heart of CVE-2019-10092, while a phishing attack could be executed via the flaws described in CVE-2019-10098, which carries a CVSS Base Score of 3.7. The HTTP Server (powered by Apache) fun wraps up with CVE-2019-10097, which carries a DOS threat with a CVSS Base Score of 5.6.

    IBM fixed these six HTTP Server flaws with a series of PTFs. Check out the security bulletin for the exact PTFs that apply to IBM i 7.2 through 7.4. (Note: Not all of the OSes are impacted by all of the flaws.)

    On September 26, when IBM issued this security alert to let IBM i customers know about a eight security flaws that were fixed in Node.js. All eight of the flaws – which were identified by the Common Vulnerably and Exposure (CVE) database with numbers CVE-2019-9511 to CVE-2019-9518 – are a denial of service (DOS) attacks that carry a Common Vulnerability Scoring System (CVSS) Base Score of 7.5. The patches impact IBM i 7.2 through 7.4.

    On August 28, IBM issued this security alert to alert customer of a new vulnerability that’s been fixed in OpenSSL on IBM i versions 7.1 through 7.4. The flaw, which is due to an error in a cipher, could let attackers access protected resources. It carries a CVSS Base Score of 4.8.

    On August 24, IBM issued this security alert to address CVE-2019-4536, which describes a flaw in Db2 Mirror for IBM i that could allow an attacker to gain access to elevated privileges upon the restoration of a user profile. The flaw carried a CVSS Base Score of 6.7; the fix applies only to IBM i 7.4, which is required for Db2 Mirror.

    On August 15, IBM issued this security alert to address CVE-2019-6471, which is tied to an ISC BIND vulnerability in IBM i that could allow an attacker to carry out a DOS attack. It features a CVSS Base Score of 5.9 and was patched on every OS from IBM i 7.1 to 7.4.

    On July 10, IBM issued this security alert to address three security vulnerabilities in the IBM i HTTP Server. The flaws, including CVE-2019-0220, CVE-2019-0196, and CVE-2019-0197, could allow attackers to launch DOS attacks. All three sport a CVSS Base Score of 5.3 and impact IBM i 7.2, 7.3, and 7.4.

    IBM issued hundreds of patches for vulnerabilities in dozens of products, from WebSphere and Java runtimes to Rational products and MQ, but none of the other security bulletins going back to July 1, 2019, featured the phrase “IBM i” in the headline, according to the IBM PSIRT Blog.

    RELATED STORIES

    IBM Patches New Security Flaws in Java, OpenSSL

    Serious Security Vulns Patched In IBM i

    IBM Patches Security Flaws In IBM i

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: Apache HTTP Server, Carriage Return Line Feed, CFLF, Common Vulnerability Scoring System, Common Vulnerably and Exposure, CVE, CVSS, Db2 Mirror, Db2 Mirror for IBM i, DOS, HTTP, IBM i, IBM i HTTP Server, IBM i PTF Guide, IBM Navigator, ISC BIND, Java, Node.js, OpenSSL, PASE, PTF, Python, Samba, Unix, WebSphere

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Four Hundred Monitor, December 4 HelpSystems Bolsters Data Loss Prevention with Clearswift Buy

    Leave a Reply Cancel reply

TFH Volume: 29 Issue: 72

This Issue Sponsored By

  • Blair Technology Solutions
  • ProData Computer Services
  • Syniti, formerly BackOffice Associates
  • ARCAD Software
  • Raz-Lee Security

Table of Contents

  • Nagios Solidifies Role in IBM i Monitoring
  • HelpSystems Bolsters Data Loss Prevention with Clearswift Buy
  • Samba Patch Caps Busy Year for IBM i Security
  • Four Hundred Monitor, December 4
  • IBM i PTF Guide, Volume 21, Number 48

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle