CVE-2018-1462: High severity ibm storwize unified v7000 vulnerability
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticated user to access system files they should not have access to including deleting files or causing a denial of service. IBM X-Force ID: 140363.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1462?
CVE-2018-1462 is classified as a medium severity vulnerability due to improper access control allowing authenticated users to access sensitive system files.
How do I fix CVE-2018-1462?
To fix CVE-2018-1462, update the affected IBM storage firmware to the latest version provided by IBM.
What products are affected by CVE-2018-1462?
CVE-2018-1462 affects various versions of IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize, and IBM FlashSystem products.
Can an attacker exploit CVE-2018-1462 remotely?
No, an attacker needs to be authenticated to the system to exploit CVE-2018-1462.
Is there a workaround for CVE-2018-1462?
There are no official workarounds for CVE-2018-1462; applying the latest firmware update is recommended for protection.