SB2023022137 - Information disclosure in IBM FlashSystem models 840 and 900
Published: February 21, 2023
Security Bulletin ID
SB2023022137
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2017-5647)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The weakness exists in the handling of the pipelined requests when send file was used resulted in the pipelined request being lost when send file processing of the previous request completed. A remote attacker can cause responses to appear to be sent for the wrong request.
Remediation
Install update from vendor's website.