First published: Sat Jun 21 2014(Updated: )
IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storwize Unified V7000 Software | =1.3.0.0 | |
IBM Storwize Unified V7000 Software | =1.3.1.0 | |
IBM Storwize Unified V7000 Software | =1.4.0.0 | |
IBM Storwize Unified V7000 Software | =1.4.0.1 | |
IBM Storwize Unified V7000 Software | =1.4.0.2 | |
IBM Storwize Unified V7000 Software | =1.4.0.3 | |
IBM Storwize Unified V7000 Software | =1.4.0.4 | |
IBM Storwize Unified V7000 Software | =1.4.0.5 | |
IBM Storwize Unified V7000 Software | =1.4.1.0 | |
IBM Storwize Unified V7000 Software | =1.4.1.1 | |
IBM Storwize Unified V7000 Software | =1.4.2.0 | |
IBM Storwize Unified V7000 Software | =1.4.2.1 | |
IBM Storwize Unified V7000 Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6737 is considered a medium severity vulnerability due to the potential exposure of sensitive customer data.
To fix CVE-2013-6737, upgrade the IBM System Storage Storwize V7000 Unified software to version 1.4.3.0 or higher.
CVE-2013-6737 affects users of IBM System Storage Storwize V7000 Unified versions 1.3.x and 1.4.x prior to 1.4.3.0.
CVE-2013-6737 allows remote authenticated users to access sensitive fragments of customer data from the exposed dump file.
The vulnerability in CVE-2013-6737 is caused by improper restrictions on the content of dump files when a 1691 hardware fault occurs.