Security Bulletin
Summary
IBM Aspera has discovered a security vulnerability that requires your immediate attention. Certain Aspera applications (details below) are vulnerable to a buffer overflow, which could allow an attacker with intimate knowledge of the system to execute commands in a restricted shell (aspshell). Aspera strongly recommends that the patch be applied to systems running the latest release of your product in order to ensure that you have all of the latest enhancements and security patches that have been provided with previous releases. The patch binary will also work with prior releases.
NOTE: The patch instructions only apply to installations that were made prior to April 13, 2020. Downloads provided thereafter have the security vulnerability remediated and do not require the patch.
Vulnerability Details
CVSS Base score: 8.1
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Products and Versions
Affected Products |
Versions |
Aspera High-Speed Transfer Server |
All versions affected |
Aspera High-Speed Transfer Endpoint |
All versions affected |
Aspera Proxy |
All versions affected |
Aspera Streaming |
All versions affected |
Aspera Application Platform On Demand |
All versions affected |
Aspera Faspex On Demand |
All versions affected |
Aspera Server On Demand |
All versions affected |
Aspera Shares On Demand |
All versions affected |
Aspera Transfer Cluster Manager |
All versions affected |
Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I) |
All versions affected |
Remediation/Fixes
Products |
VRMF |
APAR |
Remediation/First Fix |
Aspera High-Speed Transfer Server |
3.9.6 + aspshell patch |
ATT-1196 |
|
Aspera High-Speed Transfer Endpoint |
3.9.6 + aspshell patch |
ATT-1196 |
|
Aspera Proxy |
1.4.4 + aspshell patch |
ATT-1196 |
|
Aspera Streaming |
3.9.6 + aspshell patch |
ATT-1196 |
|
Aspera Application Platform On Demand |
3.9.6 + aspshell patch |
ATT-1196 |
- Contact your IBM sales rep for access to the latest released image (3.9.6) |
Aspera Faspex On Demand | 3.9.6 + aspshell patch | ATT-1196 |
- Contact your IBM sales rep for access to the latest released image (3.9.6) |
Aspera Server On Demand |
3.9.6 + aspshell patch |
ATT-1196 |
- Contact your IBM sales rep for access to the latest released image (3.9.6) |
Aspera Shares On Demand |
3.9.6 + aspshell patch |
ATT-1196 |
- Contact your IBM sales rep for access to the latest released image (3.9.6) |
Aspera Transfer Cluster Manager |
1.3.1 + aspshell patch |
ATT-1196 |
|
Aspera High-Speed Transfer Server for Cloud Pak for Integration (CP4I) |
3.9.12 |
ATT-1196 |
- Access your charts to get the latest version |
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Acknowledgement
Change History
30 Mar 2020: Initial Publication
31 Mar 2020: Update link to instructions and patch
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
20 February 2022
UID
ibm16131703