PT-2024-13334 · Ibm · Ibm Ds8900F Hmc
Published
2024-03-07
·
Updated
2025-03-11
·
CVE-2023-46171
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM DS8900F HMC versions 89.21.19.0 through 89.33.48.0
Description
The issue allows an authenticated user to view sensitive log information after enumerating filenames.
Recommendations
For versions 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0, consider restricting access to sensitive log information to prevent unauthorized viewing.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Ds8900F Hmc