IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7148023 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/283986 | vdb entry vendor advisory |