First published: Fri Apr 08 2022(Updated: )
IBM System Storage DS8000 Management Console (HMC) could allow a remote attacker to obtain sensitive information through unpublished URLs.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM R9.1 | <=89.1x.0.0 | |
IBM R9.2 | <=89.2x.0.0 | |
IBM R8.5 | <=88.5x.x.x | |
Ibm System Storage Ds8000 Management Console Firmware | =88.50.0.0 | |
Ibm System Storage Ds8000 Management Console Firmware | =89.10.0.0 | |
Ibm System Storage Ds8000 Management Console Firmware | =89.20.0.0 | |
IBM System Storage DS8000 Management Console |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-38929.
CVE-2021-38929 has a severity level of 7.5 (High).
The affected software for CVE-2021-38929 includes IBM System Storage DS8000 Management Console (HMC) versions R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0.
A remote attacker can exploit CVE-2021-38929 to obtain sensitive information through unpublished URLs.
You can find more information about CVE-2021-38929 on the IBM X-Force ID page: [https://exchange.xforce.ibmcloud.com/vulnerabilities/210330](https://exchange.xforce.ibmcloud.com/vulnerabilities/210330) and the IBM support page: [https://www.ibm.com/support/pages/node/6570741](https://www.ibm.com/support/pages/node/6570741).