Security Vulnerability in HP's ContinentalClusters
10 Dec. 2000
Summary
ContinentalClusters includes the Java Runtime Environment (JRE), which suffers from a possible security hole. The impact of this vulnerability is that improper access rights may be granted in some cases.
Credit:
The information has been provided by HP Support.
Vulnerable systems:
HP9000 Series 800 running ContinentalClusters all releases A.01.0X, and A.02.00 on HP-UX release 11.00 and 11.11.
Fixing the problem
ContinentalClusters bundles the Java Runtime Environment (JRE), therefore a patch is required to address the problem therein.
To identify if you already have the patch, run the following command on each affected machine: /usr/sbin/swlist -l product PH* | grep PHSS_22678
If the patch has been installed, you will see it listed in the output of this command. If you do not have the patch, contact ITRC to obtain it (see below).
Recommended solution
If you have ContinentalClusters version A.02.00, apply patch PHSS_22678 on each affected machine.
If you have any ContinentalClusters version A.01.0X, upgrade to version A.02.00 and then apply patch PHSS_22678 on each affected machine.