CVE-2018-1775: Infoleak
Published Feb 27, 2019
·Updated
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
Affected Software
9 affected components
IBM Spectrum Virtualize Software>=7.5<=8.2
IBM Flashsystem V9000
IBM Flashsystem V9100
IBM SAN Volume Controller
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM Spectrum Virtualize Software For Public Cloud>=7.5<=8.2
Event History
Feb 27, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1775.
2
What is the severity of CVE-2018-1775?
The severity of CVE-2018-1775 is medium with a severity value of 6.5.
3
Which IBM products are affected by CVE-2018-1775?
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize, and IBM FlashSystem products versions 7.5 through 8.2 are affected by CVE-2018-1775.
4
What could an authenticated user do with CVE-2018-1775?
An authenticated user could download arbitrary files from the operating system.
5
How can I fix CVE-2018-1775?
IBM has provided a security advisory with remediation steps for CVE-2018-1775. Please refer to the IBM support document for detailed instructions.