SB2023071807 - Information disclosure in SAN Volume Controller, Storwize family and FlashSystem V9000 products
Published: July 18, 2023
Security Bulletin ID
SB2023071807
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2017-5647)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The weakness exists in the handling of the pipelined requests when send file was used resulted in the pipelined request being lost when send file processing of the previous request completed. A remote attacker can cause responses to appear to be sent for the wrong request.
Remediation
Install update from vendor's website.