First published: Wed Feb 27 2019(Updated: )
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Virtualize | >=7.5<=8.2 | |
IBM FlashSystem V9000 | ||
IBM FlashSystem V9100 Firmware | ||
IBM SAN Volume Controller Firmware | ||
IBM Storwize V3500 Firmware | ||
IBM Storwize V3700 software | ||
IBM Storwize V5000 software | ||
IBM Storwize V7000 Firmware | ||
IBM Spectrum Virtualize software For public cloud | >=7.5<=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1775.
The severity of CVE-2018-1775 is medium with a severity value of 6.5.
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize, and IBM FlashSystem products versions 7.5 through 8.2 are affected by CVE-2018-1775.
An authenticated user could download arbitrary files from the operating system.
IBM has provided a security advisory with remediation steps for CVE-2018-1775. Please refer to the IBM support document for detailed instructions.