IBM SP2 sdrd Vulnerability
BID:371
Info
IBM SP2 sdrd Vulnerability
| Bugtraq ID: | 371 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 1998 12:00AM |
| Updated: | Aug 05 1998 12:00AM |
| Credit: | This problem was discovered by Chuck Athey and Jim Garlick of Lawrence Livermore National Laboratories, it was then published by CIAC as I-079A: IBM AIX "sdrd" daemon Vulnerability on August 5, 1998. |
| Vulnerable: |
IBM Scalable POWERparallel (SP) 2.0 |
| Not Vulnerable: | |
Discussion
IBM SP2 sdrd Vulnerability
There is a vulnerability in the System Data Repository (SDR) subsystem. The SDR subsystem is used in IBM SP multi-machine parallel processing environments typically associated with Super Computing. The SDR is deisgned to allow multiple machines to share configuration and operational information. However, proper authentication is not in place in the SDR daemon 'sdrd', this allows un-authenticated users to arbitrarily pull any file off SDR hosts.
There is a vulnerability in the System Data Repository (SDR) subsystem. The SDR subsystem is used in IBM SP multi-machine parallel processing environments typically associated with Super Computing. The SDR is deisgned to allow multiple machines to share configuration and operational information. However, proper authentication is not in place in the SDR daemon 'sdrd', this allows un-authenticated users to arbitrarily pull any file off SDR hosts.
Exploit / POC
IBM SP2 sdrd Vulnerability
Last Stage of Delerium has released exploit code for this vulnerability:
Last Stage of Delerium has released exploit code for this vulnerability:
Solution / Fix
IBM SP2 sdrd Vulnerability
Solution:
IBM has the following fix available:
IBM Scalable POWERparallel (SP) 2.0
Solution:
IBM has the following fix available:
IBM Scalable POWERparallel (SP) 2.0
References
IBM SP2 sdrd Vulnerability
References:
References: