Database/Control plane, storage & DevOps

IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobs
Impact
A user who is merely allowed to submit LSF jobs can execute arbitrary commands, via an authentication weakness backed by hard-coded credentials. Job-submission rights are the lowest privilege a cluster hands out, so this promotes every tenant to command execution in the scheduler's context.
Who can reach it
A user on the local network holding ordinary LSF job-submission privileges. Affects Spectrum LSF 10.1 and LSF Suite 10.2.
What to do
Apply IBM's fix for Spectrum LSF. Hard-coded credentials mean the secret is public once the binary is - patching is the only real mitigation, network restriction only narrows who can try.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.