PT-2014-6131 · Ibm · Ibm Storwize+1
Published
2014-09-12
·
Updated
2017-08-29
·
CVE-2014-4811
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Storwize versions 3500, 3700, 5000, and 7000
SAN Volume Controller versions 6.x through 7.x before 7.2.0.8
Description
The issue allows remote attackers to reset the administrator superuser password to its default value via a direct request to the administrative IP address.
Recommendations
For SAN Volume Controller versions 6.x through 7.x before 7.2.0.8, update to version 7.2.0.8 or later to resolve the issue.
For IBM Storwize versions 3500, 3700, 5000, and 7000, update to a version that includes the fix for this issue, as no specific version is mentioned as being updated.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Storwize
Ibm San Volume Controller