CVE-2013-6737: Medium severity ibm storwize unified v7000 vulnerability
IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6737?
CVE-2013-6737 is considered a medium severity vulnerability due to the potential exposure of sensitive customer data.
How do I fix CVE-2013-6737?
To fix CVE-2013-6737, upgrade the IBM System Storage Storwize V7000 Unified software to version 1.4.3.0 or higher.
Who is affected by CVE-2013-6737?
CVE-2013-6737 affects users of IBM System Storage Storwize V7000 Unified versions 1.3.x and 1.4.x prior to 1.4.3.0.
What kind of data is exposed by CVE-2013-6737?
CVE-2013-6737 allows remote authenticated users to access sensitive fragments of customer data from the exposed dump file.
What causes CVE-2013-6737 vulnerability?
The vulnerability in CVE-2013-6737 is caused by improper restrictions on the content of dump files when a 1691 hardware fault occurs.