#VU88477 Arbitrary file upload in Storage Defender - Resiliency Service


Published: 2024-04-11

Vulnerability identifier: #VU88477

Vulnerability risk: Low

CVSSv3.1: 5.6 [CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-27261

CWE-ID: CWE-434

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
Storage Defender - Resiliency Service
Other software / Other software solutions

Vendor: IBM Corporation

Description

The vulnerability allows a privileged user in adjacent network to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload. A privileged user in adjacent network can install a potentially dangerous tar file, which could give access to subsequent systems where the package was installed.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Storage Defender - Resiliency Service : 2.0.0 - 2.0.2


External links
http://www.ibm.com/support/pages/node/7148023


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability