IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 139474.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HIBM San Volume Controller
HWIbmall versionsIBM San Volume Controller Firmware
OSIbm6.1.0.0 – 7.5.0.14 (excl.)7.7.0.0 – 7.7.1.9 (excl.)7.8.0.0 – 7.8.1.6 (excl.)8.1.1.0 – 8.1.1.2 (excl.)8.1.2.0 – 8.1.2.1 (excl.)IBM Spectrum Virtualize
APPIbm7.8.0.0 – 7.8.1.6 (excl.)8.1.2.0 – 8.1.2.1 (excl.)8.1.1.0 – 8.1.1.2 (excl.)7.7.0.0 – 7.7.1.9 (excl.)6.1.0.0 – 7.5.0.14 (excl.)IBM Spectrum Virtualize For Public Cloud
APPIbm6.1.0.0 – 7.5.0.14 (excl.)7.7.0.0 – 7.7.1.9 (excl.)7.8.0.0 – 7.8.1.6 (excl.)8.1.1.0 – 8.1.1.2 (excl.)8.1.2.0 – 8.1.2.1 (excl.)IBM Storwize V3500
HWIbmall versionsIBM Storwize V3500 Firmware
OSIbm6.1.0.0 – 7.5.0.14 (excl.)7.7.0.0 – 7.7.1.9 (excl.)7.8.0.0 – 7.8.1.6 (excl.)8.1.1.0 – 8.1.1.2 (excl.)8.1.2.0 – 8.1.2.1 (excl.)IBM Storwize V3700
HWIbmall versionsIBM Storwize V3700 Firmware
OSIbm8.1.2.0 – 8.1.2.1 (excl.)6.1.0.0 – 7.5.0.14 (excl.)7.7.0.0 – 7.7.1.9 (excl.)7.8.0.0 – 7.8.1.6 (excl.)8.1.1.0 – 8.1.1.2 (excl.)IBM Storwize V5000
HWIbmall versionsIBM Storwize V5000 Firmware
OSIbm8.1.2.0 – 8.1.2.1 (excl.)8.1.1.0 – 8.1.1.2 (excl.)7.8.0.0 – 7.8.1.6 (excl.)7.7.0.0 – 7.7.1.9 (excl.)6.1.0.0 – 7.5.0.14 (excl.)IBM Storwize V7000
HWIbmall versionsIBM Storwize V7000 Firmware
OSIbm7.8.0.0 – 7.8.1.6 (excl.)6.1.0.0 – 7.5.0.14 (excl.)8.1.2.0 – 8.1.2.1 (excl.)8.1.1.0 – 8.1.1.2 (excl.)7.7.0.0 – 7.7.1.9 (excl.)IBM Storwize V9000
HWIbmall versionsIBM Storwize V9000 Firmware
OSIbm7.7.0.0 – 7.7.1.9 (excl.)6.1.0.0 – 7.5.0.14 (excl.)8.1.2.0 – 8.1.2.1 (excl.)8.1.1.0 – 8.1.1.2 (excl.)7.8.0.0 – 7.8.1.6 (excl.)
Related vulnerabilities
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)
IBM Spectrum Virtualize — nieautoryzowany dostęp przez ponowne użycie danych uwierzytelniających
Privilege escalation w IBM Storwize V7000 Service Assistant GUI
IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial ...
IBM Spectrum Virtualize 8.3.1 could allow a remote user authenticated via LDAP to escalate their privileges an...