CVE-2018-1775
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.5 to 8.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.5 to 8.2 |
| Running on/with | Platform Versions |
|---|---|
Ibm Flashsystem V9000 | All versions |
Ibm Flashsystem V9100 | All versions |
Ibm San Volume Controller | All versions |
Ibm Storwize V3500 | All versions |
Ibm Storwize V3700 | All versions |
Ibm Storwize V5000 | All versions |
Ibm Storwize V7000 | All versions |
References (6)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.