Skip to main content

Security bulletin: Authentication bypass vulnerability in IBM SAN Volume Controller and Storwize V7000 (CVE-2012-6354)


Flash (Alert)


Abstract

Administrative access to the system via the GUI may be obtained without supplying proper credentials.

Content

VULNERABILITY DETAILS

CVE ID:

CVE-2012-6354

DESCRIPTION:

The vulnerability can be exploited by a user with access to the system's management IP interface. If successful the user can gain access with superuser privilege which will allow any modification to the configuration, including complete deletion.

CVSS:
CVSS Base Score: 7.5
CVSS Temporal Score: See http://xforce.iss.net/xforce/xfdb/80716 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)

AFFECTED PRODUCTS:

IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V3700
IBM Flex System V7000



REMEDIATION:

For IBM SAN Volume Controller, IBM Storwize V7000, V3700 and V3500, and IBM Flex System V7000 install PTF level 6.4.1.3 or 6.3.0.7.
The issue will also be fixed in PTFs on other releases (6.4.0 and 6.2.0) for IBM SAN Volume Controller and IBM Storwize V7000 in due course.

For IBM Storwize V3700 and V3500, and IBM Flex System V7000 install PTF level 6.4.1.3.

    Workaround(s):
    None

    Mitigation(s):
    Access to the system's IP interface can be restricted, for example using a private network or firewall technology.

REFERENCES:
· Complete CVSS Guide
· On-line Calculator V2
· CVE-2012-6354
· X-Force Vulnerability Database http://xforce.iss.net/xforce/xfdb/80716
RELATED INFORMATION:

none

ACKNOWLEDGEMENT:

Vulnerability reported by Marcin Mielnoczek of Narodowe Archiwum Cyfrowe (National Digital Archives)

Cross reference information
Segment Product Component Platform Version Edition
Storage Virtualization SAN Volume Controller 6.4 SAN Volume Controller 6.1, 6.2, 6.3, 6.4
Disk Storage Systems IBM Storwize V3500 (2071) 6.4 Platform Independent 6.4
Disk Storage Systems IBM Storwize V3700 (2072) 6.4 Platform Independent Not Applicable
Disk Storage Systems Flex System V7000 6.4 Platform Independent 6.4

Rate this page:

(0 users)Average rating

Copyright and trademark information

IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.

Rate this page:


(0 users)Average rating

Add comments

Document information

IBM Storwize V7000 (2076)

6.4


Version:
6.1, 6.2, 6.3, 6.4


Operating system(s):
IBM Storwize V7000


Reference #:
S1004277


Modified date:
2013-03-07

Translate my page

Content navigation