VulnerabilityModified
CVE-2018-1775
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system.
MEDIUM 6.5EPSS 1.92%
Does this matter?
Lower severity and a low EPSS score (1.92%). Track it; it rarely justifies an emergency change on its own.
Description
IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products versions 7.5 through 8.2 could allow an authenticated user to download arbitrary files from the operating system. IBM X-Force ID: 148757.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.92% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/spectrum virtualize software · ibm/spectrum virtualize software for public cloud
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/107187Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148757VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10872486Vendor Advisory
- http://www.securityfocus.com/bid/107187Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/148757VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10872486Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.