IBM System Storage DS8900F Vulnerability: Remote Anonymous Connection Possible

CVE-2024-22326
5MEDIUM

Key Information

Vendor
IBM
Status
System Storage Ds8900f
Vendor
Published:
6 June 2024

Summary

IBM System Storage DS8900F 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, and 89.40.93.0 could allow a remote user to create an LDAP connection with a valid username and empty password to establish an anonymous connection.   IBM X-Force ID: 279518.

Affected Version(s)

System Storage DS8900F = 89.22.19.0, 89.30.68.0, 89.32.40.0, 89.33.48.0, 89.40.83.0, 89.40.93.0

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
LOW
Integrity:
LOW
Availability:
LOW
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.