===================================================================== CERT-Renater Note d'Information No. 2007/VULN529 _____________________________________________________________________ DATE : 20/12/2007 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Systems running Sun Management Center. ====================================================================== Sun(sm) Alert Notification * Sun Alert ID: 103152 * Synopsis: Security Vulnerability in Sun Management Center (Sun MC) May Allow Unauthorized Access to System and Data * Category: Security * Product: Sun Management Center 3.6.1, Sun Management Center 3.6, Sun Management Center 3.5 Update 1 * BugIDs: 6562797, 6513940 * Avoidance: Patch * State: Resolved * Date Released: 18-Dec-2007 * Date Closed: 18-Dec-2007 * Date Modified: 1. Impact A default account vulnerability in the Oracle database component of Sun Management Center (Sun MC) server software may allow remote unprivileged users to gain unauthorized access to the database or execute arbitrary code with the privileges of Oracle database server. The database server runs as the unprivileged user "smcorau". 2. Contributing Factors This issue can occur in the following releases: SPARC Platform * Sun MC 3.5 Update 1 (for Solaris 8) without patch 118388-11 * Sun MC 3.5 Update 1 (for Solaris 9) without patch 118389-12 * Sun MC 3.6 (for Solaris 8) without patch 127380-01 * Sun MC 3.6 (for Solaris 9) without patch 127381-01 * Sun MC 3.6 (for Solaris 10) without patch 127383-01 * Sun MC 3.6.1 (for Solaris 8) without patch 123920-04 * Sun MC 3.6.1 (for Solaris 9) without patch 123921-04 * Sun MC 3.6.1 (for Solaris 10) without patch 123923-04 Note 1: This issue affects systems installed with Sun Management Center (Sun MC) server software. Sun Management Center (Sun MC) can be downloaded from: * http://www.sun.com/software/products/sunmanagementcenter/ Sun MC is not bundled with Solaris. Note 2: Sun MC server is not supported on the Solaris x86 platform. Note 3: Sun MC 3.5 update 1 is not supported on Solaris 10. To determine if Sun MC server is installed on a Solaris system or what version is present, the following command can be run: $ pkginfo -l SUNWessrv | grep VERSION VERSION: 3.6.1,REV=2.7.2003.08.28 If the following error message is returned, the "SUNWessrv" package and Sun MC server are not installed on the system. ERROR: information for "SUNWessrv" was not found To determine if Sun MC database server is running on the system the following command can be run: $ ps -ef | grep 'SUNWsymon/oracle' smcorau 10655 1 0 19:36:36 ? 0:00 /opt/SUNWsymon/oracle/product/8.1.7 /bin/tnslsnr smcdblistener -inherit If the output shows "tnslsnr" process, then the database server is running. 3. Symptoms There are no reliable symptoms that would indicate the described issue has been exploited to execute arbitrary commands on the system or if the database contents have been accessed. 4. Relief/Workaround There is no workaround for this issue. Please see the Resolution section below. 5. Resolution This issue is addressed in the following releases: SPARC Platform * Sun MC 3.5 Update 1 (for Solaris 8) with patch 118388-11 or later * Sun MC 3.5 Update 1 (for Solaris 9) with patch 118389-12 or later * Sun MC 3.6 (for Solaris 8) with patch 127380-01 or later * Sun MC 3.6 (for Solaris 9) with patch 127381-01 or later * Sun MC 3.6 (for Solaris 10) with patch 127383-01 or later * Sun MC 3.6.1 (for Solaris 8) with patch 123920-04 or later * Sun MC 3.6.1 (for Solaris 9) with patch 123921-04 or later * Sun MC 3.6.1 (for Solaris 10) with patch 123923-04 or later This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may contain information provided by third parties. The issues described in this Sun Alert notification may or may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the purposes contemplated by these agreements. Copyright 2000-2006 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================