Permissions, Privileges, and Access Controls in IBM Storwize V7000 Unified - CVE-2013-6737
Published: October 17, 2023
Vulnerability identifier: #VU82097
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6737
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to obtain sensitive customer-data fragments.
The vulnerability exists due to application does not properly impose security restrictions. A emote user can trigger the vulnerability to obtain sensitive customer-data fragments by reading this file after it is copied.
Affected software
IBM Storwize V7000 Unified
SAN Volume Controller and Storwize Family
SAN Volume Controller and Storwize Family
How to mitigate CVE-2013-6737
Install updates from vendor's website.
IBM Storwize V7000 Unified - update to 1.4.3.0
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.9, 7.2.0.7, 7.3.0.3
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.9, 7.2.0.7, 7.3.0.3