ZeroHour

CVE-2018-1463

CVSS 3.1
6.5 medium
EPSS
1%p71
Published
()
Modified
Description

IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to some of which could contain account credentials. IBM X-Force ID: 140368.

Vendors
ibm
Products
storwize v7000 firmware, storwize v5000 firmware, storwize v3700 firmware, storwize v3500 firmware, storwize v9000 firmware, san volume controller firmware, spectrum virtualize, spectrum virtualize for public cloud
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.