GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobs

CVE-2020-4983Control plane, storage & DevOpsIBM X-Force 192586curated

Impact

A user who is merely allowed to submit LSF jobs can execute arbitrary commands, via an authentication weakness backed by hard-coded credentials. Job-submission rights are the lowest privilege a cluster hands out, so this promotes every tenant to command execution in the scheduler's context.

Who can reach it

A user on the local network holding ordinary LSF job-submission privileges. Affects Spectrum LSF 10.1 and LSF Suite 10.2.

What to do

Apply IBM's fix for Spectrum LSF. Hard-coded credentials mean the secret is public once the binary is - patching is the only real mitigation, network restriction only narrows who can try.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.