PT-2018-12477 · Ibm · Ibm San Volume Controller+3

Jan Bee

·

Published

2018-05-17

·

Updated

2020-08-19

·

CVE-2018-1438

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 6.1 through 8.1.1
Description The issue allows an unauthenticated attacker to read arbitrary files on the system through the web handler /DLSnap.
Recommendations For versions 6.1 through 8.1.1, as a temporary workaround, consider restricting access to the /DLSnap web handler until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1438

Affected Products

Ibm Flashsystem
Ibm San Volume Controller
Ibm Spectrum Virtualize
Ibm Storwize