SB2023071807 - Information disclosure in SAN Volume Controller, Storwize family and FlashSystem V9000 products 



SB2023071807 - Information disclosure in SAN Volume Controller, Storwize family and FlashSystem V9000 products

Published: July 18, 2023

Security Bulletin ID SB2023071807
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2017-5647)

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists in the handling of the pipelined requests when send file was used resulted in the pipelined request being lost when send file processing of the previous request completed. A remote attacker can cause responses to appear to be sent for the wrong request.

Remediation

Install update from vendor's website.