IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/107187 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/148757 | vdb entry vendor advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10872486 | vendor advisory |