Security Advisory

CVE-2013-0500

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2013-10-17 00:00:00
Last updated 2024-08-06 14:25:10
Assigner ibm
CVSS score not scored
State PUBLISHED

Description

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.