CVE-2023-50948: IBM Storage Fusion HCI information disclosure
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 275671.
Other sources
IBM Storage Fusion HCI contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50948?
CVE-2023-50948 is a vulnerability that results from hard-coded credentials in IBM Storage Fusion HCI, which can lead to unauthorized access.
How do I fix CVE-2023-50948?
To fix CVE-2023-50948, apply the patch provided by IBM for versions 2.1.0 to 2.6.1 of Storage Fusion HCI.
What are the versions affected by CVE-2023-50948?
CVE-2023-50948 affects IBM Storage Fusion HCI versions 2.1.0 through 2.6.1 inclusive.
What impact does CVE-2023-50948 have on security?
The hard-coded credentials in CVE-2023-50948 can compromise the security of inbound authentication and data encryption.
Is CVE-2023-50948 an isolated vulnerability?
CVE-2023-50948 is specific to IBM Storage Fusion HCI and does not impact other IBM software products.