Cleartext storage of sensitive information in Fujitsu products - CVE-2023-39379

 

Cleartext storage of sensitive information in Fujitsu products - CVE-2023-39379

Published: August 4, 2023


Vulnerability identifier: #VU78949
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2023-39379
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to cleartext storage of sensitive information. A local user can retrieve the password for the proxy server that is configured in ISM.


Affected software

Infrastructure Manager Advanced Edition
Infrastructure Manager Advanced Edition for PRIMEFLEX
Infrastructure Manager Essential Edition

How to mitigate CVE-2023-39379

Install updates from vendor's website.

Infrastructure Manager Advanced Edition - update to 2.8.0.061
Infrastructure Manager Advanced Edition for PRIMEFLEX - update to 2.8.0.061
Infrastructure Manager Essential Edition - update to 2.8.0.061

External References

Related Security Bulletins