CVE-2013-0500 Information

Description

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol which allows remote authenticated users to obtain sensitive information modify programs or files or cause a denial of service (device crash) via a (1) CIFS (2) HTTPS (3) SCP or (4) SFTP operation.

Reference

http://www.ibm.com/support/docview.wss?uid=ssg1S1004430 https://exchange.xforce.ibmcloud.com/vulnerabilities/84839

Share on: