cbcvebase.
CVE-2018-1433
published 2018-05-17

CVE-2018-1433: IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) web handler /DownloadFile does not require authentication to read arbitrary files from the system. IBM X-Force ID: 139473.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
ibmsan_volume_controller_firmware>= 6.1.0.0 < 7.5.0.147.5.0.14
ibmsan_volume_controller_firmware>= 7.7.0.0 < 7.7.1.97.7.1.9
ibmsan_volume_controller_firmware>= 7.8.0.0 < 7.8.1.67.8.1.6
ibmsan_volume_controller_firmware>= 8.1.1.0 < 8.1.1.28.1.1.2
ibmsan_volume_controller_firmware>= 8.1.2.0 < 8.1.2.18.1.2.1
ibmspectrum_virtualize>= 6.1.0.0 < 7.5.0.147.5.0.14
ibmspectrum_virtualize>= 7.7.0.0 < 7.7.1.97.7.1.9
ibmspectrum_virtualize>= 7.8.0.0 < 7.8.1.67.8.1.6
ibmspectrum_virtualize>= 8.1.1.0 < 8.1.1.28.1.1.2
ibmspectrum_virtualize>= 8.1.2.0 < 8.1.2.18.1.2.1
ibmspectrum_virtualize_for_public_cloud>= 6.1.0.0 < 7.5.0.147.5.0.14
ibmspectrum_virtualize_for_public_cloud>= 7.7.0.0 < 7.7.1.97.7.1.9
ibmspectrum_virtualize_for_public_cloud>= 7.8.0.0 < 7.8.1.67.8.1.6
ibmspectrum_virtualize_for_public_cloud>= 8.1.1.0 < 8.1.1.28.1.1.2
ibmspectrum_virtualize_for_public_cloud>= 8.1.2.0 < 8.1.2.18.1.2.1
ibmstorwize_v3500_firmware>= 6.1.0.0 < 7.5.0.147.5.0.14
ibmstorwize_v3500_firmware>= 7.7.0.0 < 7.7.1.97.7.1.9
ibmstorwize_v3500_firmware>= 7.8.0.0 < 7.8.1.67.8.1.6
ibmstorwize_v3500_firmware>= 8.1.1.0 < 8.1.1.28.1.1.2
ibmstorwize_v3500_firmware>= 8.1.2.0 < 8.1.2.18.1.2.1
ibmstorwize_v3700_firmware>= 6.1.0.0 < 7.5.0.147.5.0.14
ibmstorwize_v3700_firmware>= 7.7.0.0 < 7.7.1.97.7.1.9
ibmstorwize_v3700_firmware>= 7.8.0.0 < 7.8.1.67.8.1.6
ibmstorwize_v3700_firmware>= 8.1.1.0 < 8.1.1.28.1.1.2
ibmstorwize_v3700_firmware>= 8.1.2.0 < 8.1.2.18.1.2.1