First published: Fri Aug 04 2023(Updated: )
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Fujitsu Software Infrastructure Manager | =2.8.0.060 | |
Fujitsu Software Infrastructure Manager | =2.8.0.060 | |
Fujitsu Software Infrastructure Manager | =2.8.0.060 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-39379.
The severity of CVE-2023-39379 is high with a severity value of 7.5.
CVE-2023-39379 affects Fujitsu Software Infrastructure Manager by storing sensitive information in clear text form, potentially exposing the password for the proxy server configured in ISM.
The versions affected by CVE-2023-39379 are 2.8.0.060 in the Advanced and Essential editions of Fujitsu Software Infrastructure Manager.
To fix CVE-2023-39379, it is recommended to update to a version of Fujitsu Software Infrastructure Manager that does not have this vulnerability, and follow the guidelines provided by Fujitsu.