IBM Support

Security bulletin: Authentication bypass vulnerability in IBM SAN Volume Controller and Storwize Family (CVE-2012-6354)

Flashes (Alerts)


Abstract

Administrative access to the system via the GUI may be obtained without supplying proper credentials.

Content

VULNERABILITY DETAILS

CVE ID:

CVE-2012-6354

DESCRIPTION:

The vulnerability can be exploited by a user with access to the system's management IP interface. If successful the user can gain access with superuser privilege which will allow any modification to the configuration, including complete deletion.

CVSS:
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80716 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

AFFECTED PRODUCTS:

IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM Flex System V7000



REMEDIATION:

For IBM SAN Volume Controller and IBM Storwize V7000 install PTF level 7.1.0.1, 6.4.1.3, 6.3.0.7 or 6.2.0.6.

For IBM Storwize V3700 and V3500, and IBM Flex System V7000 install PTF level 7.1.0.1 or 6.4.1.3.
    Workaround(s):
    None

    Mitigation(s):
    Access to the system's IP interface can be restricted, for example using a private network or firewall technology.

REFERENCES:
· Complete CVSS Guide
· On-line Calculator V2
· CVE-2012-6354
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/80716
RELATED INFORMATION:

none

ACKNOWLEDGEMENT:

Vulnerability reported by Marcin Mielnoczek of Narodowe Archiwum Cyfrowe (National Digital Archives)

[{"Product":{"code":"ST3FR7","label":"IBM Storwize V7000"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"6.4","Platform":[{"code":"","label":"IBM Storwize V7000"}],"Version":"6.1;6.2;6.3;6.4","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"STPVGU","label":"SAN Volume Controller"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"6.4","Platform":[{"code":"","label":"SAN Volume Controller"}],"Version":"6.1;6.2;6.3;6.4","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"STLM6B","label":"IBM Storwize V3500 (2071)"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"6.4","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"6.4","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"STLM5A","label":"IBM Storwize V3700 (2072)"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"6.4","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Not Applicable","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
26 September 2022

UID

ssg1S1004277