Information Disclosure in IBM FlashSystem and Storage Products
CVE-2018-1465
5.3MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 17 May 2018
What is CVE-2018-1465?
A vulnerability exists in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize, and IBM FlashSystem products that could allow an authenticated user to access the private key, potentially enabling interception of GUI communications and compromising sensitive information. This issue affects a wide range of product versions, enhancing the urgency for users to implement necessary security measures. For detailed mitigation strategies, refer to IBM's official documentation.
Affected Version(s)
FlashSystem V9000 7.5
FlashSystem V9000 7.6
FlashSystem V9000 7.6.1