Summary
A possible security vulnerability has been reported in the FlexNet Publisher lmadmin License Server Manager.
Synopsis
A possible security vulnerability has been reported in the FlexNet Publisher lmadmin License Server Manager. More specifically, it is possible that a malicious user with access to the internal network could remotely execute arbitrary code under the lmadmin user context. In response, we suggest implementing the following best practices. This remains a theoretical vulnerability only. There have been no reported exploits of this possible vulnerability, and to date it has not been reported by a Flexera Software customer.
Flexera Software will provide a patch for all affected lmadmin platforms by August 12, 2011.
Discussion
This possible vulnerability may affect all versions of the FlexNet Publisher lmadmin License Server Manager shipped since July 2008. All lmadmin supported platforms are potentially affected, even though the behavior could be different on different platforms. It is unlikely that the vendor daemons would be affected.
Potentially Affected lmadmin Platforms
| Platforms |
|
Potentially Affected FlexNet Components
Only the FlexNet Publisher lmadmin License Server Manager, which is offered as part of FlexNet Publisher would be impacted by this potential vulnerability.
License Administrator Best Practices for Mitigating Risk Exposure
The following steps are recommended as License Administrator best practices:
- Do not use the default 2700 TCP port
- Run the license server using a least privileged user account.
- Utilize the recommended security settings offered by the Operating System (OS) vendors that resist the buffer/stack overflow attacks. For example, the Data Execution Prevention (DEP) feature on Windows helps in this regard. Most OS updates also include security features that take advantage of both hardware and software based protection mechanisms against malicious code execution.
FlexNet Publisher lmadmin License Server Manager Mitigation Plan
Flexera Software is urgently addressing this issue and will provide a patch for lmadmin version 11.10 only by August 12, 2011. Lmadmin is backwards compatible and will work with all versions of FlexNet Publisher (9.2 and above).
As soon as the patch is available, we will provide another communiqué on how to get the patch.
Customers will be notified today August 3, 2011 of the possible security vulnerability, affected products and platforms, best practices, and the mitigation plan.
Additional Information
Flexera Software has been notified of two additional potential vulnerabilities with the License Server Manager and has started its investigation. We are proactively notifying you of these additional potential vulnerabilities. We have not yet confirmed whether they exist, and we are not aware of any attempts to exploit any potential vulnerability with the License Server Manager. We will continue to provide further communication regarding these potential vulnerabilities on or before August 17, 2011.
All inquiries should be directed to security@flexerasoftware.com
Related Articles
Why does the download of file "Document Library for FlexNet Publisher Licensing" from PLC 1.0, in Chrome or Explorer,doesn… 5Number of Views FlexNet Publisher lmadmin: Security Vulnerability CVE-2022-23308 Detected in Modsecurity Component 7Number of Views FlexNet Publisher lmadmin Download Links 39Number of Views Customizing Apache HTTP Server configuration using httpConfExtra for lmadmin of FlexNet Publisher 8Number of Views FlexNet Publisher lmadmin: Denial of Service Vulnerability Discovered 9Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago